CVE-2008-0122: Critical severity isc bind 9 vulnerability

Published Jan 16, 2008
·
Updated

Off-by-one error in the inetnetwork function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.

Affected Software

43 affected components
ISC BIND<=9.4.2
FreeBSD FreeBSD=6.2
FreeBSD FreeBSD=6.2-p1
FreeBSD FreeBSD=6.2-p10
FreeBSD FreeBSD=6.2-p11
FreeBSD FreeBSD=6.2-p12
FreeBSD FreeBSD=6.2-p4
FreeBSD FreeBSD=6.2-p5
FreeBSD FreeBSD=6.2-p6
FreeBSD FreeBSD=6.2-p7
FreeBSD FreeBSD=6.2-p8
FreeBSD FreeBSD=6.2-p9
FreeBSD FreeBSD=6.2-rc1
FreeBSD FreeBSD=6.2-rc2
FreeBSD FreeBSD=6.3
FreeBSD FreeBSD=6.3-p1
FreeBSD FreeBSD=6.3-p10
FreeBSD FreeBSD=6.3-p11
FreeBSD FreeBSD=6.3-p12
FreeBSD FreeBSD=6.3-p13
FreeBSD FreeBSD=6.3-p14
FreeBSD FreeBSD=6.3-p15
FreeBSD FreeBSD=6.3-p2
FreeBSD FreeBSD=6.3-p3
FreeBSD FreeBSD=6.3-p4
FreeBSD FreeBSD=6.3-p5
FreeBSD FreeBSD=6.3-p6
FreeBSD FreeBSD=6.3-p7
FreeBSD FreeBSD=6.3-p8
FreeBSD FreeBSD=6.3-p9
FreeBSD FreeBSD=6.3-rc2
FreeBSD FreeBSD=6.4
FreeBSD FreeBSD=6.4-p1
FreeBSD FreeBSD=6.4-p10
FreeBSD FreeBSD=6.4-p11
FreeBSD FreeBSD=6.4-p2
FreeBSD FreeBSD=6.4-p3
FreeBSD FreeBSD=6.4-p4
FreeBSD FreeBSD=6.4-p5
FreeBSD FreeBSD=6.4-p6
FreeBSD FreeBSD=6.4-p7
FreeBSD FreeBSD=6.4-p8
FreeBSD FreeBSD=6.4-p9

Event History

Jan 16, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
02:00 AM
DescriptionWeaknessAffected Software
Jan 17, 2008
Data Sourced
via Red Hat·04:23 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2008-0122?

CVE-2008-0122 has been classified as a high severity vulnerability due to the potential for denial of service and arbitrary code execution.

2

How do I fix CVE-2008-0122?

To fix CVE-2008-0122, update to a version of ISC BIND later than 9.4.2 which has addressed this vulnerability.

3

What software is affected by CVE-2008-0122?

CVE-2008-0122 affects ISC BIND versions 9.4.2 and earlier, particularly as utilized in FreeBSD versions 6.2 through 7.0-PRERELEASE.

4

What kind of attack can exploit CVE-2008-0122?

CVE-2008-0122 can be exploited by context-dependent attackers who provide crafted input to cause memory corruption.

5

When was CVE-2008-0122 discovered and disclosed?

CVE-2008-0122 was disclosed in early 2008, highlighting security concerns within earlier versions of ISC BIND.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203