CVE-2002-2211: ISC BIND

Medium severity, CVSS 5.0. EPSS: 8.3% chance of exploitation in the next 30 days.

BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.

Affected products

  • ISC BIND: version 4.9 only; version 4.9.2 only; version 4.9.3 only; version 4.9.4 only; version 4.9.5 only; version 4.9.6 only; …

Published 2002-12-31. Last modified 2026-06-16.