CVE Vulnerabilities

CVE-2007-2188

Published: Apr 24, 2007 | Modified: Nov 13, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.

Affected Software

Name Vendor Start Version End Version
Extremail Extremail 2.1 (including) 2.1 (including)
Extremail Extremail 2.1.1 (including) 2.1.1 (including)

References