[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-0122Date: (C)2008-01-15   (M)2023-12-22


Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1019189
http://www.securityfocus.com/archive/1/487000/100/0/threaded
SUNALERT-238493
BID-27283
SECUNIA-28367
SECUNIA-28429
SECUNIA-28487
SECUNIA-28579
SECUNIA-29161
SECUNIA-29323
SECUNIA-30313
SECUNIA-30538
SECUNIA-30718
ADV-2008-0193
ADV-2008-0703
ADV-2008-1743
FEDORA-2008-0903
FEDORA-2008-0904
FreeBSD-SA-08:02
RHSA-2008:0300
SUSE-SR:2008:006
VU#203611
freebsd-inetnetwork-bo(39670)
http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm
http://www.isc.org/index.pl?/sw/bind/bind-security.php
http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile123640&label=AIX%20libc%20inet_network%20buffer%20overflow
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4167
https://bugzilla.redhat.com/show_bug.cgi?id=429149
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488
https://issues.rpath.com/browse/RPL-2169
oval:org.mitre.oval:def:10190

CPE    13
cpe:/o:freebsd:freebsd:6.2:rc2
cpe:/a:isc:bind
cpe:/o:freebsd:freebsd:6.2:rc1
cpe:/o:freebsd:freebsd:6.3:p11
...
CWE    1
CWE-189

© SecPod Technologies