Back
CVE-2002-0029
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.
Published: Nov 29, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (18)
| Vendor | Product | Version |
|---|---|---|
| isc | bind | 4.9.2 |
| isc | bind | 4.9.3 |
| isc | bind | 4.9.4 |
| isc | bind | 4.9.5 |
| isc | bind | 4.9.6 |
| isc | bind | 4.9.7 |
| isc | bind | 4.9.8 |
| isc | bind | 4.9.9 |
| isc | bind | 4.9.10 |
| astaro | security_linux | 2.0.23 |
| astaro | security_linux | 2.0.24 |
| astaro | security_linux | 2.0.25 |
| astaro | security_linux | 2.0.26 |
| astaro | security_linux | 2.0.27 |
| astaro | security_linux | 2.0.30 |
| astaro | security_linux | 3.2.0 |
| astaro | security_linux | 3.2.10 |
| astaro | security_linux | 3.2.11 |
GitHub Security Advisory GHSA-wc7g-r6mj-mjf6
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other...
References (16)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-028.txt.asc
- ftp://patches.sgi.com/support/free/security/advisories/20021201-01-P
- http://lists.apple.com/archives/Security-announce/2002/Nov/msg00000.html
- http://www.cert.org/advisories/CA-2002-31.html Patch, Third Party Advisory, US Government Resource
- http://www.isc.org/products/BIND/bind-security.html Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10624.php Vendor Advisory
- http://www.kb.cert.org/vuls/id/844360 US Government Resource
- http://www.securityfocus.com/bid/6186
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-028.txt.asc
- ftp://patches.sgi.com/support/free/security/advisories/20021201-01-P
- http://lists.apple.com/archives/Security-announce/2002/Nov/msg00000.html
- http://www.cert.org/advisories/CA-2002-31.html Patch, Third Party Advisory, US Government Resource
- http://www.isc.org/products/BIND/bind-security.html Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10624.php Vendor Advisory
- http://www.kb.cert.org/vuls/id/844360 US Government Resource
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
9.86%
Top 5% most likely to be exploited
Threat Score
33 / 100
Data Sources
NVD
EPSS
GitHub