cbcvebase.
CVE-2008-0122
published 2008-01-16

CVE-2008-0122: Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows…

PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
12.30%
95.8th percentile
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianbind9< glibc 2.2-1 (bookworm)glibc 2.2-1 (bookworm)
debianglibc< glibc 2.2-1 (bookworm)glibc 2.2-1 (bookworm)
gnuglibc>= 0 < 2.2-12.2-1
gnuglibc>= 0 < 2.2-12.2-1
gnuglibc>= 0 < 2.2-12.2-1
gnuglibc>= 0 < 2.2-12.2-1
iscbind<= 9.4.2

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.