CVE-2002-0029

Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.

Published: 2002-11-29 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2002-0029 is rated Moderate Risk (59/100): CVSS High severity, with high exploitation likelihood (EPSS 17.52%, 95th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2002-0029

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-13 21.85% 17.52% -4.33%
2 2025-05-11 26.24% 21.85% -4.39%
3 2025-03-30 26.24%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2002-0029

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2002-0029

OS Trackers for CVE-2002-0029

vendor priority summary link
debian unimportant CVE-2002-0029 unimportant priority: Debian including 1 source packages (bind9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2002-0029
redhat high https://access.redhat.com/security/cve/CVE-2002-0029
suse medium https://www.suse.com/security/cve/CVE-2002-0029/

Affected software / configurations for CVE-2002-0029

Vendor Product Version Raw CPE
isc bind 4.9.2 cpe:2.3:a:isc:bind:4.9.2:*:*:*:*:*:*:*
isc bind 4.9.3 cpe:2.3:a:isc:bind:4.9.3:*:*:*:*:*:*:*
isc bind 4.9.4 cpe:2.3:a:isc:bind:4.9.4:*:*:*:*:*:*:*
isc bind 4.9.5 cpe:2.3:a:isc:bind:4.9.5:*:*:*:*:*:*:*
isc bind 4.9.6 cpe:2.3:a:isc:bind:4.9.6:*:*:*:*:*:*:*
isc bind 4.9.7 cpe:2.3:a:isc:bind:4.9.7:*:*:*:*:*:*:*
isc bind 4.9.8 cpe:2.3:a:isc:bind:4.9.8:*:*:*:*:*:*:*
isc bind 4.9.9 cpe:2.3:a:isc:bind:4.9.9:*:*:*:*:*:*:*
isc bind 4.9.10 cpe:2.3:a:isc:bind:4.9.10:*:*:*:*:*:*:*
astaro security_linux 2.0.23 cpe:2.3:o:astaro:security_linux:2.0.23:*:*:*:*:*:*:*
astaro security_linux 2.0.24 cpe:2.3:o:astaro:security_linux:2.0.24:*:*:*:*:*:*:*
astaro security_linux 2.0.25 cpe:2.3:o:astaro:security_linux:2.0.25:*:*:*:*:*:*:*
astaro security_linux 2.0.26 cpe:2.3:o:astaro:security_linux:2.0.26:*:*:*:*:*:*:*
astaro security_linux 2.0.27 cpe:2.3:o:astaro:security_linux:2.0.27:*:*:*:*:*:*:*
astaro security_linux 2.0.30 cpe:2.3:o:astaro:security_linux:2.0.30:*:*:*:*:*:*:*
astaro security_linux 3.2.0 cpe:2.3:o:astaro:security_linux:3.2.0:*:*:*:*:*:*:*
astaro security_linux 3.2.10 cpe:2.3:o:astaro:security_linux:3.2.10:*:*:*:*:*:*:*
astaro security_linux 3.2.11 cpe:2.3:o:astaro:security_linux:3.2.11:*:*:*:*:*:*:*

References for CVE-2002-0029

cvelogic Threat Intelligence