PT-2008-5005 · Apple · Bonjour For Windows

Publicado

2008-09-10

·

Atualizado

2018-10-30

·

CVE-2008-3630

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apple Bonjour for Windows versions prior to 1.0.5
Description The issue concerns mDNSResponder in Apple Bonjour for Windows. When an application utilizes the Bonjour API for unicast DNS, it fails to select random values for transaction IDs or source ports in DNS requests. This oversight makes it easier for remote attackers to spoof DNS responses.
Recommendations For versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-3630

Produtos afetados

Bonjour For Windows