CVE Vulnerabilities

CVE-2008-0122

Published: Jan 16, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.

Affected Software

NameVendorStart VersionEnd Version
BindIsc*9.4.2 (including)
Red Hat Enterprise Linux 5RedHatbind-30:9.3.4-6.P1.el5*
Bind9Ubuntudapper*
Bind9Ubuntudevel*
Bind9Ubuntuedgy*
Bind9Ubuntufeisty*
Bind9Ubuntugutsy*
Bind9Ubuntuhardy*
Bind9Ubuntuintrepid*
Bind9Ubuntujaunty*
Bind9Ubuntukarmic*
Bind9Ubuntulucid*
Bind9Ubuntumaverick*
Bind9Ubuntunatty*
Bind9Ubuntuupstream*

References