CVE Vulnerabilities

CVE-2007-3377

Published: Jun 25, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

Affected Software

NameVendorStart VersionEnd Version
Net_dnsNlnet_labs0.14 (including)0.14 (including)
Net_dnsNlnet_labs0.20 (including)0.20 (including)
Net_dnsNlnet_labs0.21 (including)0.21 (including)
Net_dnsNlnet_labs0.22 (including)0.22 (including)
Net_dnsNlnet_labs0.23 (including)0.23 (including)
Net_dnsNlnet_labs0.24 (including)0.24 (including)
Net_dnsNlnet_labs0.25 (including)0.25 (including)
Net_dnsNlnet_labs0.26 (including)0.26 (including)
Net_dnsNlnet_labs0.27 (including)0.27 (including)
Net_dnsNlnet_labs0.28 (including)0.28 (including)
Net_dnsNlnet_labs0.29 (including)0.29 (including)
Net_dnsNlnet_labs0.30 (including)0.30 (including)
Net_dnsNlnet_labs0.31 (including)0.31 (including)
Net_dnsNlnet_labs0.32 (including)0.32 (including)
Net_dnsNlnet_labs0.33 (including)0.33 (including)
Net_dnsNlnet_labs0.34 (including)0.34 (including)
Net_dnsNlnet_labs0.34_02 (including)0.34_02 (including)
Net_dnsNlnet_labs0.34_03 (including)0.34_03 (including)
Net_dnsNlnet_labs0.35 (including)0.35 (including)
Net_dnsNlnet_labs0.36 (including)0.36 (including)
Net_dnsNlnet_labs0.37 (including)0.37 (including)
Net_dnsNlnet_labs0.38 (including)0.38 (including)
Net_dnsNlnet_labs0.38_01 (including)0.38_01 (including)
Net_dnsNlnet_labs0.38_02 (including)0.38_02 (including)
Net_dnsNlnet_labs0.39 (including)0.39 (including)
Net_dnsNlnet_labs0.39_01 (including)0.39_01 (including)
Net_dnsNlnet_labs0.39_02 (including)0.39_02 (including)
Net_dnsNlnet_labs0.40 (including)0.40 (including)
Net_dnsNlnet_labs0.40_01 (including)0.40_01 (including)
Net_dnsNlnet_labs0.41 (including)0.41 (including)
Net_dnsNlnet_labs0.42 (including)0.42 (including)
Net_dnsNlnet_labs0.42_01 (including)0.42_01 (including)
Net_dnsNlnet_labs0.42_02 (including)0.42_02 (including)
Net_dnsNlnet_labs0.43 (including)0.43 (including)
Net_dnsNlnet_labs0.44 (including)0.44 (including)
Net_dnsNlnet_labs0.44_01 (including)0.44_01 (including)
Net_dnsNlnet_labs0.44_02 (including)0.44_02 (including)
Net_dnsNlnet_labs0.45 (including)0.45 (including)
Net_dnsNlnet_labs0.45_01 (including)0.45_01 (including)
Net_dnsNlnet_labs0.46 (including)0.46 (including)
Net_dnsNlnet_labs0.47 (including)0.47 (including)
Net_dnsNlnet_labs0.47_01 (including)0.47_01 (including)
Net_dnsNlnet_labs0.48 (including)0.48 (including)
Net_dnsNlnet_labs0.48_01 (including)0.48_01 (including)
Net_dnsNlnet_labs0.48_02 (including)0.48_02 (including)
Net_dnsNlnet_labs0.48_03 (including)0.48_03 (including)
Net_dnsNlnet_labs0.49 (including)0.49 (including)
Net_dnsNlnet_labs0.49_01 (including)0.49_01 (including)
Net_dnsNlnet_labs0.49_02 (including)0.49_02 (including)
Net_dnsNlnet_labs0.49_03 (including)0.49_03 (including)
Net_dnsNlnet_labs0.50 (including)0.50 (including)
Net_dnsNlnet_labs0.51 (including)0.51 (including)
Net_dnsNlnet_labs0.51_01 (including)0.51_01 (including)
Net_dnsNlnet_labs0.51_02 (including)0.51_02 (including)
Net_dnsNlnet_labs0.52 (including)0.52 (including)
Net_dnsNlnet_labs0.53 (including)0.53 (including)
Net_dnsNlnet_labs0.53_01 (including)0.53_01 (including)
Net_dnsNlnet_labs0.53_02 (including)0.53_02 (including)
Net_dnsNlnet_labs0.54 (including)0.54 (including)
Net_dnsNlnet_labs0.55 (including)0.55 (including)
Net_dnsNlnet_labs0.56 (including)0.56 (including)
Net_dnsNlnet_labs0.57 (including)0.57 (including)
Net_dnsNlnet_labs0.58 (including)0.58 (including)
Net_dnsNlnet_labs0.59 (including)0.59 (including)
Red Hat Enterprise Linux 3RedHatperl-Net-DNS-0:0.31-4.el3*
Red Hat Enterprise Linux 4RedHatperl-Net-DNS-0:0.48-2.el4*
Red Hat Enterprise Linux 5RedHatperl-Net-DNS-0:0.59-3.el5*
Libnet-dns-perlUbuntudapper*
Libnet-dns-perlUbuntuedgy*
Libnet-dns-perlUbuntufeisty*
Libnet-dns-perlUbuntuupstream*

References