CVE Vulnerabilities

CVE-2010-0362

Published: Jan 20, 2010 | Modified: May 06, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Zeus Web Server before 4.3r5 does not use random transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses.

Affected Software

Name Vendor Start Version End Version
Zeus_web_server Zeus * 4.3 (including)
Zeus_web_server Zeus 3.3 (including) 3.3 (including)
Zeus_web_server Zeus 3.3.1 (including) 3.3.1 (including)
Zeus_web_server Zeus 3.3.2 (including) 3.3.2 (including)
Zeus_web_server Zeus 3.3.3 (including) 3.3.3 (including)
Zeus_web_server Zeus 3.3.4 (including) 3.3.4 (including)
Zeus_web_server Zeus 3.3.5 (including) 3.3.5 (including)
Zeus_web_server Zeus 3.3.6 (including) 3.3.6 (including)
Zeus_web_server Zeus 3.3.7 (including) 3.3.7 (including)
Zeus_web_server Zeus 3.3.8 (including) 3.3.8 (including)
Zeus_web_server Zeus 3.4 (including) 3.4 (including)
Zeus_web_server Zeus 4.1 (including) 4.1 (including)
Zeus_web_server Zeus 4.1-r1 (including) 4.1-r1 (including)
Zeus_web_server Zeus 4.2 (including) 4.2 (including)
Zeus_web_server Zeus 4.2-r2 (including) 4.2-r2 (including)
Zeus_web_server Zeus 4.3 (including) 4.3 (including)
Zeus_web_server Zeus 4.3-r3 (including) 4.3-r3 (including)

References