CVE-2008-0122: Critical severity isc bind 9 vulnerability
Off-by-one error in the inetnetwork function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0122?
CVE-2008-0122 has been classified as a high severity vulnerability due to the potential for denial of service and arbitrary code execution.
How do I fix CVE-2008-0122?
To fix CVE-2008-0122, update to a version of ISC BIND later than 9.4.2 which has addressed this vulnerability.
What software is affected by CVE-2008-0122?
CVE-2008-0122 affects ISC BIND versions 9.4.2 and earlier, particularly as utilized in FreeBSD versions 6.2 through 7.0-PRERELEASE.
What kind of attack can exploit CVE-2008-0122?
CVE-2008-0122 can be exploited by context-dependent attackers who provide crafted input to cause memory corruption.
When was CVE-2008-0122 discovered and disclosed?
CVE-2008-0122 was disclosed in early 2008, highlighting security concerns within earlier versions of ISC BIND.