CVE-2002-1146
EPSS 10.2%
Description
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
How to fix CVE-2002-1146
To remediate CVE-2002-1146, upgrade the affected package to a fixed version below.
- Debian/glibc—upgrade to 2.3 or later
Is CVE-2002-1146 being exploited?
Moderate — EPSS is 10.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.3