CVE-2008-0122
published 2008-01-16CVE-2008-0122: Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows…
PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
12.30%
95.8th percentile
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < glibc 2.2-1 (bookworm) | glibc 2.2-1 (bookworm) |
| debian | glibc | < glibc 2.2-1 (bookworm) | glibc 2.2-1 (bookworm) |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
| gnu | glibc | >= 0 < 2.2-1 | 2.2-1 |
| isc | bind | <= 9.4.2 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qfv4-7qhr-3fj9: Off-by-one error in the inet_network function in libbind in ISC BIND 9
ghsa_unreviewed·2022-05-01
CVE-2008-0122 [HIGH] GHSA-qfv4-7qhr-3fj9: Off-by-one error in the inet_network function in libbind in ISC BIND 9
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
OSV
CVE-2008-0122: Off-by-one error in the inet_network function in libbind in ISC BIND 9
osv·2008-01-16·CVSS 10.0
CVE-2008-0122 [CRITICAL] CVE-2008-0122: Off-by-one error in the inet_network function in libbind in ISC BIND 9
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Red Hat
libbind off-by-one buffer overflow
vendor_redhat·2008-01-14·CVSS 10.0
CVE-2008-0122 [CRITICAL] CWE-193 libbind off-by-one buffer overflow
libbind off-by-one buffer overflow
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Statement: This issue did not affect the versions of GNU libc as shipped with Red Hat
Enterprise Linux 2.1, 3, 4, or 5.
This issue affects the versions of libbind as shipped with Red Hat Enterprise
Linux 2.1, 3, 4, and 5, however the vulnerable function is not used by any
shipped applications. The Red Hat Security Response Team has therefore rated
this issue as having low security impact, a future update may address this flaw.
https://bugzilla.redhat.com/bu
BSD
FreeBSD-SA-08:02.libc: inet_network() buffer overflow
bsd_advisories·2008-01-14·CVSS 10.0
CVE-2008-0122 [CRITICAL] FreeBSD-SA-08:02.libc: inet_network() buffer overflow
FreeBSD-SA-08:02.libc Security Advisory
The FreeBSD Project
Topic: inet_network() buffer overflow
Category: core
Module: libc
Announced: 2008-01-14
Credits: Bjoern A. Zeeb and Nate Eldredge
Affects: FreeBSD 6.2
Corrected: 2008-01-14 22:57:45 UTC (RELENG_7, 7.0-PRERELEASE)
2008-01-14 22:55:54 UTC (RELENG_7_0, 7.0-RC2)
2008-01-14 22:56:05 UTC (RELENG_6, 6.3-PRERELEASE)
2008-01-14 22:56:18 UTC (RELENG_6_3, 6.3-RELEASE)
2008-01-14 22:56:44 UTC (RELENG_6_2, 6.2-RELEASE-p10)
CVE Name: CVE-2008-0122
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The resolver is the part of libc that resolves hostnames (example.com) to
internet protocol (IP) addresses (192.0.
Debian
CVE-2008-0122: bind9 - Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and e...
vendor_debian·2008·CVSS 10.0
CVE-2008-0122 [CRITICAL] CVE-2008-0122: bind9 - Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and e...
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.htmlhttp://secunia.com/advisories/28367http://secunia.com/advisories/28429http://secunia.com/advisories/28487http://secunia.com/advisories/28579http://secunia.com/advisories/29161http://secunia.com/advisories/29323http://secunia.com/advisories/30313http://secunia.com/advisories/30538http://secunia.com/advisories/30718http://security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.aschttp://sunsolve.sun.com/search/document.do?assetkey=1-26-238493-1http://support.avaya.com/elmodocs2/security/ASA-2008-244.htmhttp://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.kb.cert.org/vuls/id/203611http://www.redhat.com/support/errata/RHSA-2008-0300.htmlhttp://www.securityfocus.com/archive/1/487000/100/0/threadedhttp://www.securityfocus.com/bid/27283http://www.securitytracker.com/id?1019189http://www.vupen.com/english/advisories/2008/0193http://www.vupen.com/english/advisories/2008/0703http://www.vupen.com/english/advisories/2008/1743/referenceshttp://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile123640&label=AIX%20libc%20inet_network%20buffer%20overflowhttp://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4167https://bugzilla.redhat.com/show_bug.cgi?id=429149https://exchange.xforce.ibmcloud.com/vulnerabilities/39670https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://issues.rpath.com/browse/RPL-2169https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10190https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00781.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00782.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.htmlhttp://secunia.com/advisories/28367http://secunia.com/advisories/28429http://secunia.com/advisories/28487http://secunia.com/advisories/28579http://secunia.com/advisories/29161http://secunia.com/advisories/29323http://secunia.com/advisories/30313http://secunia.com/advisories/30538http://secunia.com/advisories/30718http://security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.aschttp://sunsolve.sun.com/search/document.do?assetkey=1-26-238493-1http://support.avaya.com/elmodocs2/security/ASA-2008-244.htmhttp://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.kb.cert.org/vuls/id/203611http://www.redhat.com/support/errata/RHSA-2008-0300.htmlhttp://www.securityfocus.com/archive/1/487000/100/0/threadedhttp://www.securityfocus.com/bid/27283http://www.securitytracker.com/id?1019189http://www.vupen.com/english/advisories/2008/0193http://www.vupen.com/english/advisories/2008/0703http://www.vupen.com/english/advisories/2008/1743/referenceshttp://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile123640&label=AIX%20libc%20inet_network%20buffer%20overflowhttp://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4167https://bugzilla.redhat.com/show_bug.cgi?id=429149https://exchange.xforce.ibmcloud.com/vulnerabilities/39670https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://issues.rpath.com/browse/RPL-2169https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10190https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00781.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00782.html
2008-01-16
Published