Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bind | Isc | * | 9.4.2 (including) |
Red Hat Enterprise Linux 5 | RedHat | bind-30:9.3.4-6.P1.el5 | * |
Bind9 | Ubuntu | dapper | * |
Bind9 | Ubuntu | devel | * |
Bind9 | Ubuntu | edgy | * |
Bind9 | Ubuntu | feisty | * |
Bind9 | Ubuntu | gutsy | * |
Bind9 | Ubuntu | hardy | * |
Bind9 | Ubuntu | intrepid | * |
Bind9 | Ubuntu | jaunty | * |
Bind9 | Ubuntu | karmic | * |
Bind9 | Ubuntu | lucid | * |
Bind9 | Ubuntu | maverick | * |
Bind9 | Ubuntu | natty | * |
Bind9 | Ubuntu | upstream | * |