CVE-2001-0013

BIND 4 - Remote Code Execution via Format String in nslookupComplain

Title source: llm
STIX 2.1

Description

Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-007.html
Various Sources vendor-advisory x_refsource_nai
http://www.nai.com/research/covert/advisories/047.asp
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2309
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2001-02.html

Scores

EPSS 0.1867
EPSS Percentile 95.4%

Details

Status published
Products (4)
isc/bind 4.9.3
isc/bind 4.9.5 (2 CPE variants)
isc/bind 4.9.6
isc/bind 4.9.7
Published Feb 12, 2001
Tracked Since Feb 18, 2026