CVE-2002-0684
Estado: ModificadaAlta (7.5)—
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.86%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000507
- http://marc.info/?l=bugtraq&m=102581482511612&w=2
- http://rhn.redhat.com/errata/RHSA-2002-139.html
- http://www.kb.cert.org/vuls/id/542971
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-050.php
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000507
- http://marc.info/?l=bugtraq&m=102581482511612&w=2
- http://rhn.redhat.com/errata/RHSA-2002-139.html
- http://www.kb.cert.org/vuls/id/542971
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-050.php
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0684",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-08-12T04:00:00.000",
"references": [
{
"url": "http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000507",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=102581482511612&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2002-139.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/542971",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-050.php",
"source": "cve@mitre.org"
},
{
"url": "http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000507",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=102581482511612&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2002-139.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/542971",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-050.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en las funciones de resolución de DNS que buscan nombres de red y direcciones, como en BIND 4.9.8 y glibc 2.2.5 y anteriores, permiten que servidores DNS remotos ejecuten código arbitrario por medio de una subrutina usada por funciones tales como getnetbyname y getnetbyaddr."
}
],
"lastModified": "2026-06-16T21:57:56.450",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5272D01-D7FC-41DA-B565-9054AA55FABD",
"versionEndIncluding": "2.2.5"
},
{
"criteria": "cpe:2.3:a:isc:bind:4.9.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0064E411-C26F-4831-B7C4-63E2E1EF98DF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}