CVE-2002-1146
published 2002-10-11CVE-2002-1146: The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.28%
87.1th percentile
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.3 (bookworm) | glibc 2.3 (bookworm) |
| gnu | glibc | <= 2.2.5 | — |
| gnu | glibc | >= 0 < 2.3 | 2.3 |
| gnu | glibc | >= 0 < 2.3 | 2.3 |
| gnu | glibc | >= 0 < 2.3 | 2.3 |
| gnu | glibc | >= 0 < 2.3 | 2.3 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-10-03·CVSS 5.0
CVE-2002-1146 [MEDIUM] security flaw
security flaw
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
Debian
CVE-2002-1146: glibc - The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as g...
vendor_debian·2002·CVSS 5.0
CVE-2002-1146 [MEDIUM] CVE-2002-1146: glibc - The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as g...
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
Scope: local
bookworm: resolved (fixed in 2.3)
bullseye: resolved (fixed in 2.3)
forky: resolved (fixed in 2.3)
sid: resolved (fixed in 2.3)
trixie: resolved (fixed in 2.3)
GHSA
GHSA-6w68-qf8p-27ph: The BIND 4 and BIND 8
ghsa_unreviewed·2022-05-03
CVE-2002-1146 [MEDIUM] GHSA-6w68-qf8p-27ph: The BIND 4 and BIND 8
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
OSV
CVE-2002-1146: The BIND 4 and BIND 8
osv·2002-10-11·CVSS 5.0
CVE-2002-1146 [MEDIUM] CVE-2002-1146: The BIND 4 and BIND 8
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
No detection rules found.
No public exploits indexed.
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-015.txt.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535http://www.iss.net/security_center/static/10295.phphttp://www.kb.cert.org/vuls/id/738331http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:009http://www.redhat.com/support/errata/RHSA-2002-197.htmlhttp://www.redhat.com/support/errata/RHSA-2002-258.htmlhttp://www.redhat.com/support/errata/RHSA-2003-022.htmlhttp://www.redhat.com/support/errata/RHSA-2003-212.htmlftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-015.txt.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535http://www.iss.net/security_center/static/10295.phphttp://www.kb.cert.org/vuls/id/738331http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:009http://www.redhat.com/support/errata/RHSA-2002-197.htmlhttp://www.redhat.com/support/errata/RHSA-2002-258.htmlhttp://www.redhat.com/support/errata/RHSA-2003-022.htmlhttp://www.redhat.com/support/errata/RHSA-2003-212.html
2002-10-11
Published