CVE Vulnerabilities

CVE-2007-2188

Published: Apr 24, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.

Affected Software

NameVendorStart VersionEnd Version
ExtremailExtremail2.1 (including)2.1 (including)
ExtremailExtremail2.1.1 (including)2.1.1 (including)

References