CVE Vulnerabilities

CVE-2007-3152

Published: Jun 11, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.

Affected Software

NameVendorStart VersionEnd Version
C-aresDaniel_stenberg1.0 (including)1.0 (including)
C-aresDaniel_stenberg1.1 (including)1.1 (including)
C-aresDaniel_stenberg1.2 (including)1.2 (including)
C-aresDaniel_stenberg1.2.1 (including)1.2.1 (including)
C-aresDaniel_stenberg1.3 (including)1.3 (including)
C-aresDaniel_stenberg1.3.1 (including)1.3.1 (including)
C-aresDaniel_stenberg1.3.2 (including)1.3.2 (including)

References