FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-3152

This CVE name corresponds to:

Entered Topic
2007-06-09 c-ares -- DNS Cache Poisoning Vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-3152
Phase Assigned(20070611)

Description

c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.

References

Source Reference
CONFIRM http://cool.haxx.se/cvs.cgi/curl/ares/CHANGES?rev=HEAD&content-type=text/vnd.viewcvs-markup
BID 24386
OSVDB 37171
SECUNIA 25579
XF cares-transactionid-dns-spoofing(34979)