Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Advisories
Source ID Title
EUVD EUVD EUVD-2008-0135 Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html cve-icon cve-icon
http://secunia.com/advisories/28367 cve-icon cve-icon
http://secunia.com/advisories/28429 cve-icon cve-icon
http://secunia.com/advisories/28487 cve-icon cve-icon
http://secunia.com/advisories/28579 cve-icon cve-icon
http://secunia.com/advisories/29161 cve-icon cve-icon
http://secunia.com/advisories/29323 cve-icon cve-icon
http://secunia.com/advisories/30313 cve-icon cve-icon
http://secunia.com/advisories/30538 cve-icon cve-icon
http://secunia.com/advisories/30718 cve-icon cve-icon
http://security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.asc cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238493-1 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm cve-icon cve-icon
http://www.isc.org/index.pl?/sw/bind/bind-security.php cve-icon cve-icon
http://www.kb.cert.org/vuls/id/203611 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0300.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/487000/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/27283 cve-icon cve-icon
http://www.securitytracker.com/id?1019189 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0193 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0703 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1743/references cve-icon cve-icon
http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&heading=AIX61&path=/200802/SECURITY/20080227/datafile123640&label=AIX%20libc%20inet_network%20buffer%20overflow cve-icon cve-icon
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4167 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=429149 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/39670 cve-icon cve-icon
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-2169 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-0122 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10190 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-0122 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00781.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00782.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published:

Updated: 2024-08-07T07:32:24.383Z

Reserved: 2008-01-07T00:00:00

Link: CVE-2008-0122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2008-01-16T02:00:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2008-0122

cve-icon Redhat

Severity : Low

Publid Date: 2008-01-14T00:00:00Z

Links: CVE-2008-0122 - Bugzilla

cve-icon OpenCVE Enrichment

No data.