CVE-2002-2213Path Equivalence: 'filename.' (Trailing Dot) in Bind

Severity
5.0MEDIUMNVD
EPSS
6.9%
top 8.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDisc/bind23 versions+22

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x529-934r-2q9p: The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to con2022-04-30
CVEList
CVE-2002-2213: The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to con2006-05-23

📐Framework References

1
CWE
Path Equivalence: 'filename.' (Trailing Dot)
CVE-2002-2213 — ISC Bind vulnerability | cvebase