CVE Vulnerabilities

CVE-2008-0122

Published: Jan 16, 2008 | Modified: Aug 01, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.

Affected Software

Name Vendor Start Version End Version
Bind Isc * 9.4.2 (including)
Red Hat Enterprise Linux 5 RedHat bind-30:9.3.4-6.P1.el5 *
Bind9 Ubuntu dapper *
Bind9 Ubuntu devel *
Bind9 Ubuntu edgy *
Bind9 Ubuntu feisty *
Bind9 Ubuntu gutsy *
Bind9 Ubuntu hardy *
Bind9 Ubuntu intrepid *
Bind9 Ubuntu jaunty *
Bind9 Ubuntu karmic *
Bind9 Ubuntu lucid *
Bind9 Ubuntu maverick *
Bind9 Ubuntu natty *
Bind9 Ubuntu upstream *

References