CVE-2008-0122

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
16/01/2008
Last modified:
09/04/2025

Description

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.4.2 (including)
cpe:2.3:o:freebsd:freebsd:6.2:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p10:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p11:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p12:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:rc1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.2:rc2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:6.3:-:*:*:*:*:*:*


References to Advisories, Solutions, and Tools