CVE Vulnerabilities

CVE-2007-3377

Published: Jun 25, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

Affected Software

Name Vendor Start Version End Version
Net_dns Nlnet_labs 0.14 (including) 0.14 (including)
Net_dns Nlnet_labs 0.20 (including) 0.20 (including)
Net_dns Nlnet_labs 0.21 (including) 0.21 (including)
Net_dns Nlnet_labs 0.22 (including) 0.22 (including)
Net_dns Nlnet_labs 0.23 (including) 0.23 (including)
Net_dns Nlnet_labs 0.24 (including) 0.24 (including)
Net_dns Nlnet_labs 0.25 (including) 0.25 (including)
Net_dns Nlnet_labs 0.26 (including) 0.26 (including)
Net_dns Nlnet_labs 0.27 (including) 0.27 (including)
Net_dns Nlnet_labs 0.28 (including) 0.28 (including)
Net_dns Nlnet_labs 0.29 (including) 0.29 (including)
Net_dns Nlnet_labs 0.30 (including) 0.30 (including)
Net_dns Nlnet_labs 0.31 (including) 0.31 (including)
Net_dns Nlnet_labs 0.32 (including) 0.32 (including)
Net_dns Nlnet_labs 0.33 (including) 0.33 (including)
Net_dns Nlnet_labs 0.34 (including) 0.34 (including)
Net_dns Nlnet_labs 0.34_02 (including) 0.34_02 (including)
Net_dns Nlnet_labs 0.34_03 (including) 0.34_03 (including)
Net_dns Nlnet_labs 0.35 (including) 0.35 (including)
Net_dns Nlnet_labs 0.36 (including) 0.36 (including)
Net_dns Nlnet_labs 0.37 (including) 0.37 (including)
Net_dns Nlnet_labs 0.38 (including) 0.38 (including)
Net_dns Nlnet_labs 0.38_01 (including) 0.38_01 (including)
Net_dns Nlnet_labs 0.38_02 (including) 0.38_02 (including)
Net_dns Nlnet_labs 0.39 (including) 0.39 (including)
Net_dns Nlnet_labs 0.39_01 (including) 0.39_01 (including)
Net_dns Nlnet_labs 0.39_02 (including) 0.39_02 (including)
Net_dns Nlnet_labs 0.40 (including) 0.40 (including)
Net_dns Nlnet_labs 0.40_01 (including) 0.40_01 (including)
Net_dns Nlnet_labs 0.41 (including) 0.41 (including)
Net_dns Nlnet_labs 0.42 (including) 0.42 (including)
Net_dns Nlnet_labs 0.42_01 (including) 0.42_01 (including)
Net_dns Nlnet_labs 0.42_02 (including) 0.42_02 (including)
Net_dns Nlnet_labs 0.43 (including) 0.43 (including)
Net_dns Nlnet_labs 0.44 (including) 0.44 (including)
Net_dns Nlnet_labs 0.44_01 (including) 0.44_01 (including)
Net_dns Nlnet_labs 0.44_02 (including) 0.44_02 (including)
Net_dns Nlnet_labs 0.45 (including) 0.45 (including)
Net_dns Nlnet_labs 0.45_01 (including) 0.45_01 (including)
Net_dns Nlnet_labs 0.46 (including) 0.46 (including)
Net_dns Nlnet_labs 0.47 (including) 0.47 (including)
Net_dns Nlnet_labs 0.47_01 (including) 0.47_01 (including)
Net_dns Nlnet_labs 0.48 (including) 0.48 (including)
Net_dns Nlnet_labs 0.48_01 (including) 0.48_01 (including)
Net_dns Nlnet_labs 0.48_02 (including) 0.48_02 (including)
Net_dns Nlnet_labs 0.48_03 (including) 0.48_03 (including)
Net_dns Nlnet_labs 0.49 (including) 0.49 (including)
Net_dns Nlnet_labs 0.49_01 (including) 0.49_01 (including)
Net_dns Nlnet_labs 0.49_02 (including) 0.49_02 (including)
Net_dns Nlnet_labs 0.49_03 (including) 0.49_03 (including)
Net_dns Nlnet_labs 0.50 (including) 0.50 (including)
Net_dns Nlnet_labs 0.51 (including) 0.51 (including)
Net_dns Nlnet_labs 0.51_01 (including) 0.51_01 (including)
Net_dns Nlnet_labs 0.51_02 (including) 0.51_02 (including)
Net_dns Nlnet_labs 0.52 (including) 0.52 (including)
Net_dns Nlnet_labs 0.53 (including) 0.53 (including)
Net_dns Nlnet_labs 0.53_01 (including) 0.53_01 (including)
Net_dns Nlnet_labs 0.53_02 (including) 0.53_02 (including)
Net_dns Nlnet_labs 0.54 (including) 0.54 (including)
Net_dns Nlnet_labs 0.55 (including) 0.55 (including)
Net_dns Nlnet_labs 0.56 (including) 0.56 (including)
Net_dns Nlnet_labs 0.57 (including) 0.57 (including)
Net_dns Nlnet_labs 0.58 (including) 0.58 (including)
Net_dns Nlnet_labs 0.59 (including) 0.59 (including)
Red Hat Enterprise Linux 3 RedHat perl-Net-DNS-0:0.31-4.el3 *
Red Hat Enterprise Linux 4 RedHat perl-Net-DNS-0:0.48-2.el4 *
Red Hat Enterprise Linux 5 RedHat perl-Net-DNS-0:0.59-3.el5 *
Libnet-dns-perl Ubuntu dapper *
Libnet-dns-perl Ubuntu edgy *
Libnet-dns-perl Ubuntu feisty *
Libnet-dns-perl Ubuntu upstream *

References