PT-2007-4228 · Isc+2 · Isc Bind+2
Amit Klein
·
Published
2007-09-11
·
Updated
2018-10-16
·
CVE-2007-2930
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ISC BIND 8 versions prior to 8.4.7-P1
Description
The issue affects the NSID SHUFFLE ONLY and NSID USE POOL PRNG algorithms, which generate predictable DNS query identifiers when sending outgoing queries, such as NOTIFY messages, when answering questions as a resolver. This allows remote attackers to poison DNS caches via unknown vectors.
Recommendations
For versions prior to 8.4.7-P1, update to version 8.4.7-P1 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bind Server
Hp-Ux
Isc Bind