CVE-2002-2212
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same…
Does this matter?
Lower severity and a low EPSS score (2.40%). Track it; it rarely justifies an emergency change on its own.
Description
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.40% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- isc/bind · fujitsu/uxp v
- Source
- cve@mitre.org
References
- http://www.imconf.net/imw-2002/imw2002-papers/198.pdf
- http://www.kb.cert.org/vuls/id/457875US Government Resource
- http://www.kb.cert.org/vuls/id/IAFY-5FDT5K
- http://www.rnp.br/cais/alertas/2002/cais-ALR-19112002a.htmlPatch
- http://www.imconf.net/imw-2002/imw2002-papers/198.pdf
- http://www.kb.cert.org/vuls/id/457875US Government Resource
- http://www.kb.cert.org/vuls/id/IAFY-5FDT5K
- http://www.rnp.br/cais/alertas/2002/cais-ALR-19112002a.htmlPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.