20021112 Multiple Remote Vulnerabilities in BIND4 and BIND8Third-party advisory
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21469 CVE-2002-1220
ISC BIND 8.3.x - OPT Record Large UDP Denial of Service
Record summary
CVE-2002-1220 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBISC BIND 8.3.x - OPT Record Large UDP Denial of ServiceExploitDB exploitby spybreakNot analyzed1 file
References
Showing 12 of 162002-11-21Vendor advisory
http://lists.apple.com/archives/Security-announce/2002/Nov/msg00000.html 20021112 [Fwd: Notice of serious vulnerabilities in ISC BIND 4 & 8]mailing list
http://marc.info/?l=bugtraq&m=103713117612842&w=2 20021118 TSLSA-2002-0076 - bindmailing list
http://marc.info/?l=bugtraq&m=103763574715133&w=2 SSRT2408Vendor advisory
http://online.securityfocus.com/advisories/4999 20021115 [OpenPKG-SA-2002.011] OpenPKG Security Advisory (bind, bind8)mailing list
http://online.securityfocus.com/archive/1/300019 CA-2002-31Third-party advisory
http://www.cert.org/advisories/CA-2002-31.html N-013Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/n-013.shtml DSA-196Vendor advisory
http://www.debian.org/security/2002/dsa-196 isc.orgConfirmation
http://www.isc.org/products/BIND/bind-security.html VU#229595Third-party advisory
http://www.kb.cert.org/vuls/id/229595 MDKSA-2002:077Vendor advisory
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-077.php