Vulnerability Name: | CVE-2008-4099 (CCN-45938) | ||||||||||||||||
Assigned: | 2008-07-10 | ||||||||||||||||
Published: | 2008-07-10 | ||||||||||||||||
Updated: | 2008-09-19 | ||||||||||||||||
Summary: | PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-16 | ||||||||||||||||
Vulnerability Consequences: | Other | ||||||||||||||||
References: | Source: CCN Type: Debian Bug report logs - #490217 python-dns vulnerable to CVE-2008-1447 DNS source port guessable Source: CONFIRM Type: Exploit http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490217 Source: MITRE Type: CNA CVE-2008-4099 Source: CONFIRM Type: UNKNOWN http://packages.debian.org/changelogs/pool/main/p/python-dns/python-dns_2.3.3-1/changelog Source: CCN Type: python-dns Web page Source Package: python-dns Source: DEBIAN Type: DSA-1619 python-dns -- DNS response spoofing Source: CCN Type: oss-security Mailing List, Thu, 11 Sep 2008 11:06:33 +0200 Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Source: MLIST Type: UNKNOWN [oss-security] 20080911 Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Source: CCN Type: oss-security Mailing List, Mon, 15 Sep 2008 20:59:40 -0400 (EDT) Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Source: MLIST Type: UNKNOWN [oss-security] 20080915 Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Source: XF Type: UNKNOWN pydns-dns-spoofing(45938) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |