CVE-2002-1219 describes a buffer overflow vulnerability in BIND versions 4.9.10 and earlier, and 8.3.3 and earlier, impacting various FreeBSD, ISC, and OpenBSD products. This flaw allows remote attackers to execute arbitrary code by crafting a malicious DNS server response containing specific SIG resource records. With a CVSS score of 7.5, it represents a high-severity risk, requiring no authentication and low attack complexity to achieve partial confidentiality, integrity, and availability compromise. While no active exploitation or public exploit code is noted, and community discussion is minimal, its EPSS score indicates a higher-than-average likelihood of exploitation compared to most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.9.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:4.9.5:*:*:*:*:*:*:* | ||
4.9.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:4.9.6:*:*:*:*:*:*:* | ||
4.9.7CPE matchmatch criteria | cpe:2.3:a:isc:bind:4.9.7:*:*:*:*:*:*:* | ||
4.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:4.9.8:*:*:*:*:*:*:* | ||
4.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:4.9.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.