First published: Wed Jan 16 2008(Updated: )
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Credit: secteam@freebsd.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC BIND 9 | <=9.4.2 | |
FreeBSD Kernel | =6.2 | |
FreeBSD Kernel | =6.2-p1 | |
FreeBSD Kernel | =6.2-p10 | |
FreeBSD Kernel | =6.2-p11 | |
FreeBSD Kernel | =6.2-p12 | |
FreeBSD Kernel | =6.2-p4 | |
FreeBSD Kernel | =6.2-p5 | |
FreeBSD Kernel | =6.2-p6 | |
FreeBSD Kernel | =6.2-p7 | |
FreeBSD Kernel | =6.2-p8 | |
FreeBSD Kernel | =6.2-p9 | |
FreeBSD Kernel | =6.2-rc1 | |
FreeBSD Kernel | =6.2-rc2 | |
FreeBSD Kernel | =6.3 | |
FreeBSD Kernel | =6.3-p1 | |
FreeBSD Kernel | =6.3-p10 | |
FreeBSD Kernel | =6.3-p11 | |
FreeBSD Kernel | =6.3-p12 | |
FreeBSD Kernel | =6.3-p13 | |
FreeBSD Kernel | =6.3-p14 | |
FreeBSD Kernel | =6.3-p15 | |
FreeBSD Kernel | =6.3-p2 | |
FreeBSD Kernel | =6.3-p3 | |
FreeBSD Kernel | =6.3-p4 | |
FreeBSD Kernel | =6.3-p5 | |
FreeBSD Kernel | =6.3-p6 | |
FreeBSD Kernel | =6.3-p7 | |
FreeBSD Kernel | =6.3-p8 | |
FreeBSD Kernel | =6.3-p9 | |
FreeBSD Kernel | =6.3-rc2 | |
FreeBSD Kernel | =6.4 | |
FreeBSD Kernel | =6.4-p1 | |
FreeBSD Kernel | =6.4-p10 | |
FreeBSD Kernel | =6.4-p11 | |
FreeBSD Kernel | =6.4-p2 | |
FreeBSD Kernel | =6.4-p3 | |
FreeBSD Kernel | =6.4-p4 | |
FreeBSD Kernel | =6.4-p5 | |
FreeBSD Kernel | =6.4-p6 | |
FreeBSD Kernel | =6.4-p7 | |
FreeBSD Kernel | =6.4-p8 | |
FreeBSD Kernel | =6.4-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0122 has been classified as a high severity vulnerability due to the potential for denial of service and arbitrary code execution.
To fix CVE-2008-0122, update to a version of ISC BIND later than 9.4.2 which has addressed this vulnerability.
CVE-2008-0122 affects ISC BIND versions 9.4.2 and earlier, particularly as utilized in FreeBSD versions 6.2 through 7.0-PRERELEASE.
CVE-2008-0122 can be exploited by context-dependent attackers who provide crafted input to cause memory corruption.
CVE-2008-0122 was disclosed in early 2008, highlighting security concerns within earlier versions of ISC BIND.