← Vulnerability feed

Vulnerability record · CVE-2002-0400 · published 18 June 2002

CVE-2002-0400: Isc bind vulnerability

Isc · Bind

ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL, aka DoS_findtype.

5.0 CVSS 2.0 Medium EPSS 14% · top 3.5%
5.0CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL, aka DoS_findtype.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.24.1/CSSA-2002-SCO.24.1.txt
http://archives.neohapsis.com/archives/hp/2002-q3/0022.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000494
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:038
http://www.cert.org/advisories/CA-2002-15.html PatchThird Party AdvisoryUS Government Resource
http://www.isc.org/index.pl?/sw/bind/bind-security.php
http://www.iss.net/security_center/static/9250.php Vendor Advisory
http://www.kb.cert.org/vuls/id/739123 PatchThird Party AdvisoryUS Government Resource
http://www.novell.com/linux/security/advisories/2002_21_bind9.html
http://www.redhat.com/support/errata/RHSA-2002-105.html
http://www.redhat.com/support/errata/RHSA-2002-119.html
http://www.redhat.com/support/errata/RHSA-2003-154.html
http://www.securityfocus.com/bid/4936
ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.24.1/CSSA-2002-SCO.24.1.txt
http://archives.neohapsis.com/archives/hp/2002-q3/0022.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000494
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:038
http://www.cert.org/advisories/CA-2002-15.html PatchThird Party AdvisoryUS Government Resource
http://www.isc.org/index.pl?/sw/bind/bind-security.php
http://www.iss.net/security_center/static/9250.php Vendor Advisory
http://www.kb.cert.org/vuls/id/739123 PatchThird Party AdvisoryUS Government Resource
http://www.novell.com/linux/security/advisories/2002_21_bind9.html
http://www.redhat.com/support/errata/RHSA-2002-105.html
http://www.redhat.com/support/errata/RHSA-2002-119.html
http://www.redhat.com/support/errata/RHSA-2003-154.html
http://www.securityfocus.com/bid/4936

Track CVE-2002-0400 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2002-0400), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.