CVE Vulnerabilities

CVE-2010-0362

Published: Jan 20, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zeus Web Server before 4.3r5 does not use random transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses.

Affected Software

NameVendorStart VersionEnd Version
Zeus_web_serverZeus*4.3 (including)
Zeus_web_serverZeus3.3 (including)3.3 (including)
Zeus_web_serverZeus3.3.1 (including)3.3.1 (including)
Zeus_web_serverZeus3.3.2 (including)3.3.2 (including)
Zeus_web_serverZeus3.3.3 (including)3.3.3 (including)
Zeus_web_serverZeus3.3.4 (including)3.3.4 (including)
Zeus_web_serverZeus3.3.5 (including)3.3.5 (including)
Zeus_web_serverZeus3.3.6 (including)3.3.6 (including)
Zeus_web_serverZeus3.3.7 (including)3.3.7 (including)
Zeus_web_serverZeus3.3.8 (including)3.3.8 (including)
Zeus_web_serverZeus3.4 (including)3.4 (including)
Zeus_web_serverZeus4.1 (including)4.1 (including)
Zeus_web_serverZeus4.1-r1 (including)4.1-r1 (including)
Zeus_web_serverZeus4.2 (including)4.2 (including)
Zeus_web_serverZeus4.2-r2 (including)4.2-r2 (including)
Zeus_web_serverZeus4.3 (including)4.3 (including)
Zeus_web_serverZeus4.3-r3 (including)4.3-r3 (including)

References