CVE-2008-0122
Summary
| CVE | CVE-2008-0122 |
|---|---|
| State | PUBLISHED |
| Assigner | freebsd |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-16 02:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Freebsd | Freebsd | 6.2 | - | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p1 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p10 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p11 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p12 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p4 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p5 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p6 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p7 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p8 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | p9 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | rc1 | All | All |
| Operating System | Freebsd | Freebsd | 6.2 | rc2 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | - | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p1 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p10 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p11 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p12 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p13 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p14 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p15 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p2 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p3 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p4 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p5 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p6 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p7 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p8 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | p9 | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | rc2 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | - | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p1 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p10 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p11 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p2 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p3 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p4 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p5 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p6 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p7 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p8 | All | All |
| Operating System | Freebsd | Freebsd | 6.4 | p9 | All | All |
| Application | Isc | Bind | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.asc | af854a3a-2127-422b-91ae-364da2661108 | security.freebsd.org | Patch, Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Fedora update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| ISC has a new website | Internet Systems Consortium | af854a3a-2127-422b-91ae-364da2661108 | www.isc.org | Vendor Advisory |
| IBM AIX libc "inet_network()" Off-By-One Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM - My notifications | af854a3a-2127-422b-91ae-364da2661108 | www14.software.ibm.com | Third Party Advisory |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20564.www2.hpe.com | Third Party Advisory |
| FreeBSD "inet_network()" Off-By-One Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| ASA-2008-244 (SUN 238493) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | Third Party Advisory |
| Avaya CMS Solaris "inet_network()" Off-By-One Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| US-CERT Vulnerability Note VU#203611 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:006 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| Bug 429149 – CVE-2008-0122 libbind off-by-one buffer overflow | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Multiple Vendors BIND 'inet_network()' Off-by-One Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Third Party Advisory, VDB Entry |
| issues.rpath.com/browse/RPL-2169 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | Third Party Advisory |
| www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd | af854a3a-2127-422b-91ae-364da2661108 | www14.software.ibm.com | Third Party Advisory |
| [SECURITY] Fedora 8 Update: bind-9.5.0-23.b1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Sun Solaris "inet_network()" Off-By-One Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| ISC BIND libbind "inet_network()" Off-By-One Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| SecurityTracker.com Archives - FreeBSD libc Buffer Overflow in inet_network() May Let Users Deny Service or Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 7 Update: bind-9.4.2-3.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| rPath update for bind and bind-utils - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-05-21 | Mark J Cox | This issue did not affect the versions of GNU libc as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. This issue affects the versions of libbind as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5, however the vulnerable function is not used by any shipped applications. The Red Hat Security Response Team has therefore rated this issue as having low security impact, a future update may address this flaw. https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-0122 An update to Red Hat Enterprise Linux 5 was released to correct this issue: https://rhn.redhat.com/errata/RHSA-2008-0300.html |
There are currently no legacy QID mappings associated with this CVE.