CVE Vulnerabilities

CVE-2007-3152

Published: Jun 11, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.

Affected Software

Name Vendor Start Version End Version
C-ares Daniel_stenberg 1.0 (including) 1.0 (including)
C-ares Daniel_stenberg 1.1 (including) 1.1 (including)
C-ares Daniel_stenberg 1.2 (including) 1.2 (including)
C-ares Daniel_stenberg 1.2.1 (including) 1.2.1 (including)
C-ares Daniel_stenberg 1.3 (including) 1.3 (including)
C-ares Daniel_stenberg 1.3.1 (including) 1.3.1 (including)
C-ares Daniel_stenberg 1.3.2 (including) 1.3.2 (including)

References