Multiple Vendor libc DNS Resolver Buffer Overflow Vulnerability

BID:5100

Info

Multiple Vendor libc DNS Resolver Buffer Overflow Vulnerability

Bugtraq ID: 5100
Class: Boundary Condition Error
CVE: CVE-2002-0651
Remote: Yes
Local: No
Published: Jun 26 2002 12:00AM
Updated: Jul 11 2009 01:56PM
Credit: Discovered by Joost Pol <[email protected]>.
Vulnerable: Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1
Sun Solaris 9
Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 2.6_x86
Sun Solaris 2.6
SCO Open Server 5.0.6
SCO Open Server 5.0.5
OpenBSD OpenBSD 2.9
OpenBSD OpenBSD 2.8
OpenBSD OpenBSD 2.7
OpenBSD OpenBSD 3.1
OpenBSD OpenBSD 3.0
NetBSD NetBSD 1.5.3
NetBSD NetBSD 1.5.2
NetBSD NetBSD 1.5.1
NetBSD NetBSD 1.5 x86
NetBSD NetBSD 1.5 sh3
NetBSD NetBSD 1.5
NetBSD NetBSD 1.4.3
NetBSD NetBSD 1.4.2 x86
NetBSD NetBSD 1.4.2 SPARC
NetBSD NetBSD 1.4.2 arm32
NetBSD NetBSD 1.4.2 Alpha
NetBSD NetBSD 1.4.2
NetBSD NetBSD 1.4.1 x86
NetBSD NetBSD 1.4.1 SPARC
NetBSD NetBSD 1.4.1 sh3
NetBSD NetBSD 1.4.1 arm32
NetBSD NetBSD 1.4.1 Alpha
NetBSD NetBSD 1.4.1
NetBSD NetBSD 1.4 x86
NetBSD NetBSD 1.4 SPARC
NetBSD NetBSD 1.4 arm32
NetBSD NetBSD 1.4 Alpha
NetBSD NetBSD 1.4
ISC BIND 9.2.1
+ Caldera OpenUnix 8.0
+ MandrakeSoft Single Network Firewall 7.2
+ Mandriva Linux Mandrake 7.2
+ SCO Unixware 7.1.3
ISC BIND 9.2
ISC BIND 9.1.3
ISC BIND 9.1.2
+ SuSE Linux 7.2 i386
+ SuSE Linux 7.2
ISC BIND 9.1.1
ISC BIND 9.1
+ Caldera OpenUnix 8.0
+ HP Secure OS software for Linux 1.0
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.1
+ SuSE Linux 7.1 x86
+ SuSE Linux 7.1 sparc
+ SuSE Linux 7.1 ppc
+ SuSE Linux 7.1 alpha
+ SuSE Linux 7.1
ISC BIND 9.0
+ SuSE Linux 7.0 sparc
+ SuSE Linux 7.0 ppc
+ SuSE Linux 7.0 i386
+ SuSE Linux 7.0 alpha
+ SuSE Linux 7.0
ISC BIND 8.2.5
+ OpenPKG OpenPKG 1.0
+ Trustix Secure Linux 1.5
ISC BIND 8.2.4
+ SuSE Linux 8.1
+ SuSE Linux 8.0
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3
+ Trustix Secure Linux 1.2
ISC BIND 8.2.3
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Debian Linux 2.2
+ EnGarde Secure Linux 1.0.1
+ Immunix Immunix OS 7+
ISC BIND 8.2.2 p7
ISC BIND 8.2.2 p6
ISC BIND 8.2.2 p5
+ Caldera OpenLinux Desktop 2.3
+ Caldera UnixWare 7.1.1
+ Debian Linux 2.3 sparc
+ Debian Linux 2.3 powerpc
+ Debian Linux 2.3 arm
+ Debian Linux 2.3 alpha
+ Debian Linux 2.3 68k
+ Debian Linux 2.3
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ IBM AIX 4.3.3
+ IBM AIX 4.3.2
+ IBM AIX 4.3.1
+ IBM AIX 4.3
+ MandrakeSoft Corporate Server 1.0.1
+ MandrakeSoft Single Network Firewall 7.2
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.1
+ Mandriva Linux Mandrake 7.0
+ Mandriva Linux Mandrake 6.1
+ Mandriva Linux Mandrake 6.0
+ Redhat Linux 7.0 J sparc
+ Redhat Linux 7.0 J i386
+ Redhat Linux 7.0 J alpha
+ Redhat Linux 7.0 sparc
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux 6.2 E sparc
+ Redhat Linux 6.2 E i386
+ Redhat Linux 6.2 E alpha
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
+ Redhat Linux 6.1 sparc
+ Redhat Linux 6.1 i386
+ Redhat Linux 6.1 alpha
+ Redhat Linux 6.0 sparc
+ Redhat Linux 6.0 alpha
+ Redhat Linux 6.0
+ Redhat Linux 5.2 sparc
+ Redhat Linux 5.2 i386
+ Redhat Linux 5.2 alpha
+ SCO eDesktop 2.4
+ SCO eServer 2.3
+ SuSE Linux 6.4 ppc
+ SuSE Linux 6.4 alpha
+ SuSE Linux 6.4
+ SuSE Linux 6.3 alpha
+ SuSE Linux 6.3
+ SuSE Linux 6.2
+ SuSE Linux 6.1 alpha
+ SuSE Linux 6.1
+ SuSE Linux 6.0
+ Trustix Trustix Secure Linux 1.1
+ Trustix Trustix Secure Linux 1.0
ISC BIND 8.2.2 p4
ISC BIND 8.2.2 p3
ISC BIND 8.2.2 p2
ISC BIND 8.2.2 p1
ISC BIND 8.2.2
ISC BIND 8.2.1
ISC BIND 8.2
- Caldera OpenLinux 2.2
- Caldera OpenLinux 1.3
- Caldera UnixWare 7.1.1
- IBM AIX 4.3.3
- IBM AIX 4.3.2
- IBM AIX 4.3.1
- IBM AIX 4.3
- Redhat Linux 6.1 i386
- Redhat Linux 6.0
- Redhat Linux 5.2 i386
- Redhat Linux 5.1
- Redhat Linux 5.0
- Redhat Linux 4.2
- Redhat Linux 4.1
- Redhat Linux 4.0
- Slackware Linux 4.0
ISC BIND 8.1.2
+ HP HP-UX 11.11
+ HP HP-UX 11.0
ISC BIND 8.1.1
ISC BIND 8.1
ISC BIND 4.9.8
ISC BIND 4.9.7
+ HP HP-UX 11.0 4
+ HP HP-UX 11.0
+ HP HP-UX 10.24
+ HP HP-UX 10.20
+ HP HP-UX 10.10
ISC BIND 4.9.6
ISC BIND 4.9.5
ISC BIND 4.9.4
ISC BIND 4.9.3
ISC BIND 4.9
IBM AIX 4.3
IBM AIX 5.1
HP LaserJet 9000MFP
HP LaserJet 4100MFP
HP LaserJet 4100
HP JetDirect J6061A
HP JetDirect J6058A
HP JetDirect J6057A
HP JetDirect J6042A
HP JetDirect J6039A
HP JetDirect J6038A
HP JetDirect J6035A
HP JetDirect J4169A
HP JetDirect J4167A
HP HP-UX 11.22
HP HP-UX 11.11
HP HP-UX 11.0 4
HP HP-UX 11.0
HP HP-UX 10.24
HP HP-UX 10.20
HP HP-UX 10.10
HP Digital Sender 9100C
HP colour LaserJet 4550
HP Color LaserJet 4600 0
GNU glibc 2.2.5
GNU glibc 2.2.4
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ HP Secure OS software for Linux 1.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
+ Redhat Linux 7.2 i686
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i686
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alphaev6
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.0 alphaev6
+ Redhat Linux 7.0 i686
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux Advanced Work Station 2.1
+ S.u.S.E. Linux Database Server 0
+ S.u.S.E. Linux Enterprise Server for S/390
+ S.u.S.E. Linux Firewall on CD
+ S.u.S.E. SuSE eMail Server III
+ Sun Linux 5.0.7
+ Sun Linux 5.0.6
+ Sun Linux 5.0.5
+ Sun Linux 5.0.3
+ Sun Linux 5.0
+ SuSE Linux 8.0 i386
+ SuSE Linux 8.0
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 i386
+ SuSE Linux 7.3
+ SuSE SUSE Linux Enterprise Server 7
GNU glibc 2.2.3
GNU glibc 2.2.2
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
+ SuSE Linux 7.2 i386
+ SuSE Linux 7.2
GNU glibc 2.2.1
GNU glibc 2.2
+ SuSE Linux 7.1 x86
+ SuSE Linux 7.1 sparc
+ SuSE Linux 7.1 ppc
+ SuSE Linux 7.1 alpha
+ SuSE Linux 7.1
+ Wirex Immunix OS 7+
GNU glibc 2.1.9 and Greater
GNU glibc 2.1.3 -10
+ Debian Linux 2.2
GNU glibc 2.1.3
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ EnGarde Secure Linux 1.0.1
+ HP Secure OS software for Linux 1.0
+ MandrakeSoft Corporate Server 1.0.1
+ MandrakeSoft Single Network Firewall 7.2
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.1
+ Openwall Openwall GNU/*/Linux 0.1 -stable
+ Redhat Linux 6.2 sparcv9
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
+ Redhat Linux 6.2
+ SuSE Linux 7.0 sparc
+ SuSE Linux 7.0 ppc
+ SuSE Linux 7.0 i386
+ SuSE Linux 7.0 alpha
+ SuSE Linux 7.0
+ SuSE Linux 6.4 ppc
+ SuSE Linux 6.4 i386
+ SuSE Linux 6.4 alpha
+ SuSE Linux 6.4
+ Trustix Secure Linux 1.5
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.1
+ Trustix Secure Linux 1.0 1
GNU glibc 2.1.2
GNU glibc 2.1.1 -6
+ Redhat Linux 6.0
GNU glibc 2.1.1
GNU glibc 2.1
GNU glibc 2.0.6
GNU glibc 2.0.5
GNU glibc 2.0.4
GNU glibc 2.0.3
GNU glibc 2.0.2
GNU glibc 2.0.1
GNU glibc 2.0
FreeBSD FreeBSD 5.0 alpha
FreeBSD FreeBSD 5.0
FreeBSD FreeBSD 4.6 -RELEASE
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.5 -STABLE
FreeBSD FreeBSD 4.5 -RELEASE
FreeBSD FreeBSD 4.5
FreeBSD FreeBSD 4.4 -STABLE
FreeBSD FreeBSD 4.4 -RELENG
FreeBSD FreeBSD 4.4
FreeBSD FreeBSD 4.3 -STABLE
FreeBSD FreeBSD 4.3 -RELENG
FreeBSD FreeBSD 4.3 -RELEASE
FreeBSD FreeBSD 4.3
Cray UNICOS 9.2 .4
Cray UNICOS 9.2
Cray UNICOS 9.0.2 .5
Cray UNICOS 9.0
Cray UNICOS 8.3
Cray UNICOS 8.0
Astaro Security Linux 2.0 26
Astaro Security Linux 2.0 25
Astaro Security Linux 2.0 24
Astaro Security Linux 2.0 23
Astaro Security Linux 2.0 16
Not Vulnerable: NetBSD NetBSD 1.6
ISC BIND 9.2.2
ISC BIND 9.1.3
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i686
+ Redhat Linux 7.2 i586
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2
+ SuSE Linux 8.0 i386
+ SuSE Linux 8.0
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 i386
+ SuSE Linux 7.3
ISC BIND 9.1.2
+ SuSE Linux 7.2 i386
+ SuSE Linux 7.2
ISC BIND 9.1.1
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
ISC BIND 9.1
+ Caldera OpenUnix 8.0
+ HP Secure OS software for Linux 1.0
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.1
+ SuSE Linux 7.1 x86
+ SuSE Linux 7.1 sparc
+ SuSE Linux 7.1 ppc
+ SuSE Linux 7.1 alpha
+ SuSE Linux 7.1
ISC BIND 9.0
+ SuSE Linux 7.0 sparc
+ SuSE Linux 7.0 ppc
+ SuSE Linux 7.0 i386
+ SuSE Linux 7.0 alpha
+ SuSE Linux 7.0
ISC BIND 8.3.3
+ Apple Mac OS X 10.2.2
+ Apple Mac OS X 10.2.1
+ Apple Mac OS X 10.2
+ Apple Mac OS X 10.1.5
+ Apple Mac OS X 10.1.4
+ Apple Mac OS X 10.1.3
+ Apple Mac OS X 10.1.2
+ Apple Mac OS X 10.1.1
+ Apple Mac OS X 10.1
+ Apple Mac OS X 10.1
+ Apple Mac OS X Server 10.2.2
+ Apple Mac OS X Server 10.2.1
+ Apple Mac OS X Server 10.2
+ Apple Mac OS X Server 10.0
+ Debian Linux 3.0
+ FreeBSD FreeBSD 4.7 -RELEASE
+ FreeBSD FreeBSD 4.7
+ MandrakeSoft Single Network Firewall 7.2
+ Mandriva Linux Mandrake 7.2
+ OpenPKG OpenPKG 1.1
+ OpenPKG OpenPKG Current
ISC BIND 8.2.6
+ OpenPKG OpenPKG 1.0
+ Trustix Secure Linux 1.5
+ Trustix Secure Linux 1.2
ISC BIND 4.9.9
Astaro Security Linux 2.0 27

Exploit / POC

Multiple Vendor libc DNS Resolver Buffer Overflow Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] &lt;mailto:[email protected]&gt;.

Solution / Fix

Multiple Vendor libc DNS Resolver Buffer Overflow Vulnerability

Solution:
An initial workaround of using a trusted caching DNS server to reconstruct DNS answers was a sufficient workaround. It has since been discovered that this is not a sufficient workaround, and that the only way to properly resolve this vulnerability is to installed fixed resolver libraries.

For users of BIND 8, Tim Gladding <[email protected]> has contributed an unofficial BIND 9 patch which may alleviate some difficulties with migration involving the 'multiple-cnames yes;' option in BIND 8. Details are available in his BugTraq post, available as a reference.

Upgrade to the latest version of BIND to eliminate vulnerabilities found in earlier versions. As of this writing, the most current version is 9.2.2.

BIND is available for download from URL:
http://www.isc.org/products/BIND/bind9.html

An alternative solution is to a apply vendor specific patch. Users should check with their particular vendor to determine the status of their specific patches.

It should be noted that binaries statically linked to libc will need to be recompiled with fixed libraries.

System administrators should contact their individual vendor for upgrade or patch information to fix the BIND DNS resolver code buffer overflow vulnerability.

DNS resolver libraries can be used by multiple applications on most systems. It may be necessary to upgrade or apply multiple patches and then recompile statically linked applications.

Applications that are statically linked must be recompiled using patched resolver libraries. Applications that are dynamically linked do not need to be recompiled; however, running services need to be restarted in order to use the patched resolver libraries.

System administrators should consider the following process when addressing this issue:
1. Patch or obtain updated resolver libraries.
2. Restart any dynamically linked services that make use of the resolver libraries.
3. Recompile any statically linked applications using the patched or updated resolver libraries.

HP has released a revised advisory (HPSBUX0208-209(rev.15)) to address this issue in affected HP-UX systems. Customers who are affected by this issue are advised to apply appropriate patches. Further information regarding obtaining and applying patches is available in the referenced advisory.

HP has released an updated advisory HPSBUX0208-209(rev.14) for HP-UX systems. Preliminary updates for HP-UX 11 and 11.11 are available. Further information on obtaining and applying fixes is available in the referenced HP advisory (HPSBUX0208-209).

FreeBSD releases RELENG_4_5 and RELENG_4_6 are fixed as of 06 June 2002.

FreeBSD has released other upgrades. Users are advised to upgrade their Ports
collection and reinstall the affected port.

OpenBSD and FreeBSD patches are available.

Compaq has stated that the impact of this vulnerability is currently being investigated, and has been assigned incident number x-ref:SSRT2270.

Cray has announced that UNICOS is affected by this issue, and has assigned incident ID SPR 722619 to track this issue.

The ISC has announced that BIND 9 is also affected by this vulnerability. ISC BIND 9.2.2 has been released to address this issue in BIND 9.2.x.

Network Appliance has stated that some NetApp systems may be affected, but has not made details publicly available. Users are advised to check NOW (http://now.netapp.com) for further information.

SGI has stated that they are investigating the impact, but have made no further details available.

Apple has announced that Mac OS X and OS X Server are not affected by this issue.

Users of Astaro Secure Linux 2.x are advised to use Up2Date to upgrade to version 2.027.

Users of GNU glibc are advised to update to versions more recent than 2.1.2. Additional vulnerabilities in the process of resolving network names and addresses through DNS can be worked around by editing the file /etc/nsswitch.conf and ensuring that the 'networks:' line does not specify that DNS be used.

SuSE has suggested that users set the approriate line to read 'networks: files'. SuSE reports that updated glibc packages will be made available in the near future.

HP has recommended that users of HP Secure OS version 1.0 apply the appropriate fixes described in Red Hat Security Advisory RHSA-2002:139.

Caldera has released an advisory with updates. See the attached Caldera advisory for details on obtaining fixes.

HP has made temporary BIND upgrades available for HP-UX installations. The files are located at the following server:

System: hprc.external.hp.com (192.170.19.51)
Login: bind
Password: bind1

HP has updated the fix for HP-UX 10.20. In HP-UX 10.20, the DNS API was part of the C library. The fix now includes an update for the statically linked library. Any programs which used the DNS API must be relinked. HP claims to know of no such programs included by default, however they may be detected by issuing the following command:

strings -a suspect_program | grep "Too many addresses (%d)"

If the string is present, the suspected program should be relinked with the corrected libc.a included in PHCO_26152.depot.

HP has released an updated advisory, HPSBUX0209-218 (rev .1), stating several HP peripheral devices are vulnerable. A firmware upgrade which addresses this issue is available for HP JetDirect Print Servers. Further information on how to obtain and apply the firmware can be found in the attached advisory.

Users of EnGarde Secure Linux are advised to upgrade vulnerable glibc libraries by installing the RPMs listed in the advisory. Further details can be found in the referenced advisory.

NetBSD has issued a new advisory 2002-015. NetBSD 1.6 is not affected by this issue. Users are strongly urged to upgrade their systems to NetBSD 1.6 or to update to the most recent sources of the appropriate branches. Further details are available in the referenced NetBSD advisory.

Conectiva has released an advisory (CLA-2002:535) which contains upgrades. See the referenced advisory for further details on obtaining fixes.

A security fix was provided on October 1st, 2002 for Openwall GNU/*/Linux. Users should contact the vendor to obtain fixed glibc packages.

Red Hat has released a new advisory (RHSA-2002:197-09). Updated glibc and nscd RPMs are available. See the attached advisory for details on obtaining fixes.

Updates are available for Sorceror Linux. These updates can be applied using the following command:

augur synch && augur update

HP has updated security bulletin HPSBUX0208-209. New information about obtaining and applying fixes are available in the referenced advisory.

HP has released HPSBUX0208-209 (rev.12) containing fix information for HP-UX B.10.20 and B.11.04. See the updated advisory for details.

HP has released HPSBUX0208-209 (rev.16) containing fix information. See the updated advisory for details.

Updates are available:


Sun Solaris 8_sparc

OpenBSD OpenBSD 3.0

IBM AIX 5.1
  • IBM IY32746


Sun Solaris 7.0

OpenBSD OpenBSD 3.1

HP HP-UX 11.22

GNU glibc 2.1.3

GNU glibc 2.2.2

GNU glibc 2.2.3

GNU glibc 2.2.4

IBM AIX 4.3
  • IBM IY32719


FreeBSD FreeBSD 4.5 -RELEASE

FreeBSD FreeBSD 4.6

ISC BIND 4.9

ISC BIND 4.9.4

ISC BIND 4.9.5

ISC BIND 4.9.6

ISC BIND 4.9.7

ISC BIND 4.9.8

SCO Open Server 5.0.5

SCO Open Server 5.0.6

ISC BIND 8.1.1

ISC BIND 8.1.2

ISC BIND 8.2

ISC BIND 8.2.1

ISC BIND 8.2.2 p4

ISC BIND 8.2.2 p7

ISC BIND 8.2.2 p1

ISC BIND 8.2.2 p3

ISC BIND 8.2.2 p6

ISC BIND 8.2.2 p5

ISC BIND 8.2.3

ISC BIND 8.2.4

ISC BIND 8.2.5

ISC BIND 9.0

ISC BIND 9.1

ISC BIND 9.1.2

ISC BIND 9.2.1

References

Multiple Vendor libc DNS Resolver Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report