Input validation error in GNU C Library (glibc) - CVE-2002-0684

 

Input validation error in GNU C Library (glibc) - CVE-2002-0684

Published: October 18, 2016 / Updated: June 3, 2025


Vulnerability identifier: #VU110134
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2002-0684
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.


Affected software

GNU C Library (glibc)

How to mitigate CVE-2002-0684

Install update from vendor's website.


External References

Related Security Bulletins