PT-2007-4228 · Isc+2 · Isc Bind+2

Amit Klein

·

Published

2007-09-11

·

Updated

2018-10-16

·

CVE-2007-2930

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ISC BIND 8 versions prior to 8.4.7-P1
Description The issue affects the NSID SHUFFLE ONLY and NSID USE POOL PRNG algorithms, which generate predictable DNS query identifiers when sending outgoing queries, such as NOTIFY messages, when answering questions as a resolver. This allows remote attackers to poison DNS caches via unknown vectors.
Recommendations For versions prior to 8.4.7-P1, update to version 8.4.7-P1 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2930
HPSBUX02289

Affected Products

Bind Server
Hp-Ux
Isc Bind