Multiple vendor socket entropy DNS spoofing
| dns-socket-entropy-spoofing (43334) |
Description:
Multiple vendor DNS protocol implementations could allow a remote attacker to spoof DNS traffic. The DNS client service fails to provide an adequate amount of entropy when performing DNS queries. An attacker could exploit this vulnerability to spoof DNS traffic against certain recursive resolvers, which could allow the attacker to obtain sensitive information and redirect Internet traffic to any server of the attacker's choosing.
Platforms Affected:
- Alcatel-Lucent, VitalQIP
- Apple, iPhone 1.0
- Apple, iPhone 1.0.1
- Apple, iPhone 1.1.1
- Apple, iPhone 1.1.2
- Apple, iPhone 1.1.3
- Apple, iPhone 1.1.4
- Apple, iPhone 2.0
- Apple, iPhone 2.0.1
- Apple, iPhone 2.0.2
- Apple, iPod touch 1.1
- Apple, iPod touch 1.1.1
- Apple, iPod touch 1.1.2
- Apple, iPod touch 1.1.3
- Apple, iPod touch 1.1.4
- Apple, iPod touch 2.0
- Apple, iPod touch 2.0.1
- Apple, iPod touch 2.0.2
- Apple, Mac OS X 10.4.11
- Apple, Mac OS X 10.5
- Apple, Mac OS X 10.5.1
- Apple, Mac OS X 10.5.2
- Apple, Mac OS X 10.5.3
- Apple, Mac OS X 10.5.4
- Apple, Mac OS X Server 10.4.11
- Apple, Mac OS X Server 10.5
- Apple, Mac OS X Server 10.5.1
- Apple, Mac OS X Server 10.5.2
- Apple, Mac OS X Server 10.5.3
- Apple, Mac OS X Server 10.5.4
- Astaro, Astaro Security Gateway 6.0
- Astaro, Astaro Security Gateway 7.0
- BlueCat Networks, Adonis 4.1.0.43
- BlueCat Networks, Adonis 5.0
- BlueCat Networks, Adonis 5.1.0
- BlueCat Networks, Adonis 5.1.1
- BlueCoat, Director
- BlueCoat, ProxyRA
- BlueCoat, ProxySG
- Canonical, Ubuntu 6.06 LTS
- Canonical, Ubuntu 7.04
- Canonical, Ubuntu 7.10
- Canonical, Ubuntu 8.04 LTS
- Cisco, Application and Content Networking Software 5.5
- Cisco, CNS Network Registrar 6.1
- Cisco, CNS Network Registrar 6.3
- Cisco, CNS Network Registrar 7.0
- Cisco, IOS 12.0DB
- Cisco, IOS 12.0DC
- Cisco, IOS 12.0T
- Cisco, IOS 12.0WC
- Cisco, IOS 12.0XE
- Cisco, IOS 12.0XK
- Cisco, IOS 12.0XR
- Cisco, IOS 12.1
- Cisco, IOS 12.1AY
- Cisco, IOS 12.1DB
- Cisco, IOS 12.1DC
- Cisco, IOS 12.1EA
- Cisco, IOS 12.1EX
- Cisco, IOS 12.1T
- Cisco, IOS 12.1XC
- Cisco, IOS 12.1YE
- Cisco, IOS 12.2
- Cisco, IOS 12.2B
- Cisco, IOS 12.2BC
- Cisco, IOS 12.2BW
- Cisco, IOS 12.2BY
- Cisco, IOS 12.2CZ
- Cisco, IOS 12.2T
- Cisco, IOS 12.2TPC
- Cisco, IOS 12.2XB
- Cisco, IOS 12.2XC
- Cisco, IOS 12.2XG
- Cisco, IOS 12.2XK
- Cisco, IOS 12.2XL
- Cisco, IOS 12.2XT
- Cisco, IOS 12.2XU
- Cisco, IOS 12.2YJ
- Cisco, IOS 12.2YL
- Cisco, IOS 12.2YM
- Cisco, IOS 12.2YN
- Cisco, IOS 12.2YO
- Cisco, IOS 12.2YT
- Cisco, IOS 12.2YU
- Cisco, IOS 12.2YV
- Cisco, IOS 12.2ZB
- Cisco, IOS 12.2ZD
- Cisco, IOS 12.2ZE
- Cisco, IOS 12.2ZF
- Cisco, IOS 12.2ZG
- Cisco, IOS 12.2ZH
- Cisco, IOS 12.2ZJ
- Cisco, IOS 12.2ZL
- Cisco, IOS 12.3
- Cisco, IOS 12.3B
- Cisco, IOS 12.3BW
- Cisco, IOS 12.3T
- Cisco, IOS 12.3TPC
- Cisco, IOS 12.3VA
- Cisco, IOS 12.3XA
- Cisco, IOS 12.3XB
- Cisco, IOS 12.3XC
- Cisco, IOS 12.3XD
- Cisco, IOS 12.3XE
- Cisco, IOS 12.3XF
- Cisco, IOS 12.3XG
- Cisco, IOS 12.3XH
- Cisco, IOS 12.3XI
- Cisco, IOS 12.3XJ
- Cisco, IOS 12.3XK
- Cisco, IOS 12.3XQ
- Cisco, IOS 12.3XR
- Cisco, IOS 12.3XS
- Cisco, IOS 12.3XW
- Cisco, IOS 12.3YA
- Cisco, IOS 12.3YD
- Cisco, IOS 12.3YF
- Cisco, IOS 12.3YG
- Cisco, IOS 12.3YH
- Cisco, IOS 12.3YI
- Cisco, IOS 12.3YK
- Cisco, IOS 12.3YM
- Cisco, IOS 12.3YS
- Cisco, IOS 12.3YT
- Cisco, IOS 12.3YU
- Cisco, IOS 12.3YX
- Cisco, IOS 12.3YZ
- Cisco, IOS 12.4
- Cisco, IOS 12.4MD
- Cisco, IOS 12.4MR
- Cisco, IOS 12.4SW
- Cisco, IOS 12.4T
- Cisco, IOS 12.4XA
- Cisco, IOS 12.4XB
- Cisco, IOS 12.4XC
- Cisco, IOS 12.4XD
- Cisco, IOS 12.4XE
- Cisco, IOS 12.4XJ
- Cisco, IOS 12.4XL
- Cisco, IOS 12.4XM
- Cisco, IOS 12.4XN
- Cisco, IOS 12.4XQ
- Cisco, IOS 12.4XT
- Cisco, IOS 12.4XV
- Cisco, IOS 12.4XW
- Cisco, IOS 12.4XY
- Cisco, IOS 12.4XZ
- Citrix, Access Gateway 4.2
- Citrix, Access Gateway 4.5 Standard
- Citrix, Access Gateway 4.5 Advanced
- Citrix, NetScaler
- CyberGuard Corporation, CyberGuard Classic
- CyberGuard Corporation, CyberGuard TSP
- Debian, Debian Linux 4.0
- F5, 3 DNS
- F5, BIG-IP
- F5, Enterprise Manager
- F5, FirePass 5.5
- F5, FirePass 5.5.2
- F5, FirePass 6.0
- F5, FirePass 6.0.1
- F5, FirePass 6.0.2
- F5, WANJet
- Gentoo, Linux
- HP, HP-UX B.11.11
- HP, HP-UX B.11.23
- HP, HP-UX B.11.31
- HP, MPE iX 6.5
- HP, MPE iX 7.0
- HP, MPE iX 7.5
- HP, NonStop Server
- HP, Storage Management Appliance 2.1
- Ingate, Ingate Firewall 4.6.2
- Ingate, Ingate SIParator 4.6.2
- ISC, BIND 4
- ISC, BIND 8
- ISC, BIND 9.2.9
- MandrakeSoft, Mandrake Linux 2007.1
- MandrakeSoft, Mandrake Linux 2007.1 X86_64
- MandrakeSoft, Mandrake Linux 2008.0 X86_64
- MandrakeSoft, Mandrake Linux 2008.0
- MandrakeSoft, Mandrake Linux 2008.1 X86_64
- MandrakeSoft, Mandrake Linux 2008.1
- MandrakeSoft, Mandrake Linux Corporate Server 3.0 X86_64
- MandrakeSoft, Mandrake Linux Corporate Server 3.0
- MandrakeSoft, Mandrake Linux Corporate Server 4.0 X86_64
- MandrakeSoft, Mandrake Linux Corporate Server 4.0
- MandrakeSoft, Mandrake Multi Network Firewall 2.0
- Microsoft, Windows 2000 SP4
- Microsoft, Windows 2003 Server SP1 Itanium
- Microsoft, Windows 2003 Server SP1
- Microsoft, Windows 2003 Server x64
- Microsoft, Windows 2003 Server SP2 x64
- Microsoft, Windows 2003 Server SP2
- Microsoft, Windows 2003 Server SP2 Itanium
- Microsoft, Windows XP SP2
- Microsoft, Windows XP SP2 Professional x64
- Microsoft, Windows XP Professional x64
- Microsoft, Windows XP SP3
- Novell, Linux Desktop 9
- Novell, Linux POS 9
- Novell, NetWare
- Novell, Open Enterprise Server
- Novell, OpenSUSE 10.2
- Novell, OpenSUSE 10.3
- Novell, OpenSUSE 11.0
- Novell, SLE SDK 10 SP1
- Novell, SLE SDK 10 SP2
- Novell, SUSE Linux Enterprise 10 SP2 DEBUGINFO
- Novell, SUSE Linux Enterprise Desktop 10 SP1
- Novell, SUSE Linux Enterprise Desktop 10 SP2
- Novell, SUSE Linux Enterprise Server 10 SP1
- Novell, SUSE Linux Enterprise Server 10 SP2
- Paul A. Rombouts, pdnsd
- RedHat, Enterprise Linux 2.1 ES
- RedHat, Enterprise Linux 2.1 WS
- RedHat, Enterprise Linux 2.1 AS
- RedHat, Enterprise Linux 3 Desktop
- RedHat, Enterprise Linux 3 WS
- RedHat, Enterprise Linux 3 ES
- RedHat, Enterprise Linux 3 AS
- RedHat, Enterprise Linux 4 WS
- RedHat, Enterprise Linux 4 AS
- RedHat, Enterprise Linux 4 ES
- RedHat, Enterprise Linux 4 Desktop
- RedHat, Enterprise Linux 5 Client
- RedHat, Enterprise Linux 5 Client Workstation
- RedHat, Enterprise Linux 5
- RedHat, Linux Advanced Workstation 2.1 Itanium
- SecureComputing, Sidewinder
- Sun, OpenSolaris build_snv_01 x86
- Sun, OpenSolaris build_snv_01 SPARC
- Sun, OpenSolaris build_snv_13 SPARC
- Sun, OpenSolaris build_snv_13 x86
- Sun, OpenSolaris build_snv_19 x86
- Sun, OpenSolaris build_snv_19 SPARC
- Sun, OpenSolaris build_snv_22 x86
- Sun, OpenSolaris build_snv_22 SPARC
- Sun, OpenSolaris build_snv_64 SPARC
- Sun, OpenSolaris build_snv_64 x86
- Sun, OpenSolaris build_snv_91 x86
- Sun, OpenSolaris build_snv_91 SPARC
- Sun, OpenSolaris build_snv_92 SPARC
- Sun, OpenSolaris build_snv_92 x86
- Sun, OpenSolaris build_snv_95 x86
- Sun, OpenSolaris build_snv_95 SPARC
- Sun, Solaris 10 SPARC
- Sun, Solaris 10 x86
- Sun, Solaris 8 x86
- Sun, Solaris 8 SPARC
- Sun, Solaris 9 x86
- Sun, Solaris 9 SPARC
- SuSE, SuSE SLES 9
- Thekelleys, Dnsmasq 2.43
- Turbolinux, Turbolinux 10 Server
- Turbolinux, Turbolinux 10 Server x64 Ed
- Turbolinux, Turbolinux 11 Server
- Turbolinux, Turbolinux 11 Server x64 Ed
- Turbolinux, Turbolinux Personal
- Turbolinux, Turbolinux Appliance Server 1.0 Hosting Ed
- Turbolinux, Turbolinux Appliance Server 1.0 Workgroup Ed
- Turbolinux, Turbolinux Appliance Server 2.0
- Yamaha, RT Series Routers ja
- Yukihiro Matsumoto, Ruby 1.8
- Yukihiro Matsumoto, Ruby 1.9
Remedy:
Apply the appropriate patch for your system, as listed in the latest Microsoft Security Bulletin. See References.
— OR —
Use Microsoft Automatic Update if it is supported by your operating system. The original bulletin issued by Microsoft has been superceded.
For other distributions:
Apply the appropriate update for your system. See References.
Consequences:
Obtain Information
References:
- Alcatel-Lucent Security Advisory, Multiple DNS implementations vulnerable to cache poisoning at http://www1.alcatel-lucent.com/psirt/statements/2008003/DNScache.htm.
- Apple Web site, About the security content of Mac OS X v10.5.5 and Security Update 2008-006 at http://support.apple.com/kb/HT3137.
- Apple Web site, About the security content of iPhone v2.1 at http://support.apple.com/kb/HT3129.
- Apple Web site, About the security content of iPod touch v2.1 at http://support.apple.com/kb/HT3026.
- Apple Web site, About Security Update 2008-005 at http://support.apple.com/kb/HT2647.
- Astaro Web site, Up2Date 6.314 Released at http://up2date.astaro.com/2008/09/up2date_6314_released.html.
- Blue Coat Security Advisory, 14 July 2008, DNS CACHE POISONING VULNERABILITY (CERT VU#800113) at http://www.bluecoat.com/support/security-advisories/dns_cache_poisoning.
- BlueCat Networks Web site, Adonis at http://www.bluecatnetworks.com/products/adonis-dns-dhcp-appliances/.
- cisco-sa-20080708-dns, Cisco Security Advisory: Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks at http://www.cisco.com/warp/public/707/cisco-sa-20080708-dns.shtml.
- Citrix Systems Web site, Citrix NetScaler at http://www.citrix.com/English/ps2/products/product.asp?contentID=21679.
- CTX118183, Vulnerability in Access Gateway Standard and Advanced Edition Appliance firmware could result in DNS Cache Poisoning at http://support.citrix.com/article/CTX118183.
- Full-Disclosure Mailing List, Wed Jul 23 2008 - 18:34:26 CDT, CAU-EX-2008-0002: Kaminsky DNS Cache Poisoning Flaw Exploit at http://archives.neohapsis.com/archives/fulldisclosure/2008-07/0410.html.
- HPSBMP02404 SSRT090014 rev.1, MPE/iX Running BIND/iX, Remote DNS Cache Poisoning at http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01660723.
- HPSBNS02405 SSRT071449: rev.1, HP NonStop Server running BIND, Remote DNS Cache Poisoning at http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01662368.
- HPSBST02350 SSRT080102 rev.1, Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-037 to MS08-040 at http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01503743.
- HPSBUX02351 SSRT080058 rev.2, HP-UX Running BIND, Remote DNS Cache Poisoning at http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01506861.
- HPSBUX02351 SSRT080058 rev.3 , HP-UX Running BIND, Remote DNS Cache Poisoning at http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01506861.
- inGate Web site, Release notice for Ingate Firewall 4.6.4 and Ingate SIParator 4.6.4 at http://www.ingate.com/relnote-464.php.
- ISC Web site, CERT VU#800113 DNS Cache Poisoning Issue at http://www.isc.org/index.pl?/sw/bind/bind-security.php.
- Microsoft Security Bulletin MS08-037, Vulnerabilities in DNS Could Allow Spoofing (953230) at http://www.microsoft.com/technet/security/Bulletin/MS08-037.mspx.
- Microsoft Security Bulletin MS09-008, Vulnerabilities in DNS and WINS server could allow Spoofing (962238) at http://www.microsoft.com/technet/security/bulletin/ms09-008.mspx.
- NetBSD Security Advisory 2008-009, BIND cache poisoning at ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-009.txt.asc.
- Nominum Software Security Advisory NOM-20080708, Nominum Software Security Advisory at http://www.nominum.com/asset_upload_file741_2661.pdf.
- NORTEL BULLETIN ID: 2008008958, Rev 1, Centrex IP Client Manager (CICM) response to Microsoft July security bulletin at http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=745165.
- NORTEL BULLETIN ID: 2008008989, Rev 1, Nortel Response to Microsoft Security Bulletin MS08-037 at http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751322.
- NORTEL BULLETIN ID: 2008009038, Rev 1, Nortel Guidance for Multiple Vendor Fixes for BIND/DNS Cache Poison Vulnerability - CVE-2008-1447 at http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=762152.
- Novell Security Alert Document ID: 7000912, Status of CVE-2008-1447 - Multiple DNS implementations vulnerable to cache poisoning at http://www.novell.com/support/viewContent.do?externalId=7000912.
- pdnsd Web page, pdnsd Change Log, 2008-09-01 at http://www.phys.uu.nl/~rombouts/pdnsd/ChangeLog.
- Ruby Core SVN Repository, Ruby Core at http://www.ruby-lang.org/en/community/ruby-core/.
- Ruby Programming Language Web site, Multiple vulnerabilities in Ruby at http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/.
- Secure Computing Corporation Web Site, Enterprise Security Products at http://www.securecomputing.com/index.cfm?skey=2.
- Sun Alert ID: 239392, Security Vulnerability in the DNS Protocol may lead to DNS Cache Poisoning at http://sunsolve.sun.com/search/document.do?assetkey=1-26-239392-1.
- Sun Alert ID: 245206, Security Vulnerability in Solaris IP Filter Network Address Translation (NAT) May Lead to DNS Cache Poisoning at http://sunsolve.sun.com/search/document.do?assetkey=1-66-245206-1.
- TheKelleys.org Web page, Dnsmasq at http://www.thekelleys.org.uk/dnsmasq/doc.html.
- Yamaha RT Series Routers Home page, Yamaha RT Series Routers at http://www.rtpro.yamaha.co.jp/.
- ASA-2008-288: MS08-037 Vulnerabilities in DNS Could Allow Spoofing (953230)
- ASA-2008-319: bind security update (RHSA-2008-0533)
- BID-30131: Multiple Vendor DNS Protocol Insufficient Transaction ID Randomization DNS Spoofing Vulnerability
- BID-30132: Microsoft Windows DNS Server Cache Poisoning Vulnerability
- CVE-2008-1447: The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka DNS Insufficient Socket Entropy Vulnerability or the Kaminsky bug.
- DSA-1603: bind9 -- DNS cache poisoning
- DSA-1604: bind -- DNS cache poisoning
- DSA-1604-1: bind -- DNS cache poisoning
- DSA-1605: glibc -- DNS cache poisoning
- DSA-1617: refpolicy -- incompatible policy
- DSA-1619: python-dns -- DNS response spoofing
- DSA-1623: dnsmasq -- DNS cache poisoning
- GLSA-200807-08: BIND: Cache poisoning
- GLSA-200809-02: dnsmasq: Denial of Service and DNS spoofing
- GLSA-200812-17: Ruby: Multiple vulnerabilities
- GLSA-200901-03: pdnsd: Denial of Service and cache poisoning
- MDVSA-2008:139: Updated BIND packages fix critical DNS vulnerability
- RHSA-2008-0533: Important: bind security update
- RHSA-2008-0789: Moderate: dnsmasq security update
- SA30925: Microsoft Windows DNS Spoofing Vulnerabilities
- SA30973: ISC BIND Query Port DNS Cache Poisoning
- SA30979: Cisco Products DNS Cache Poisoning Vulnerability
- SA30980: Sun Solaris 10 DNS Cache Poisoning Vulnerability
- SA30989: Debian bind DNS Cache Poisoning Vulnerability
- SA31011: Nominum CNS and Vantio DNS Cache Poisoning Vulnerability
- SA31012: Juniper Networks Products DNS Cache Poisoning Vulnerability
- SA31014: Sun Solaris DNS Cache Poisoning Vulnerability
- SA31030: Infoblox NIOS BIND Query Port DNS Cache Poisoning
- SA31031: Nixu Secure Name Server BIND Query Port DNS Cache Poisoning
- SA31065: Novell Netware DNS Cache Poisoning Vulnerability
- SA31093: F5 Products DNS Cache Poisoning Vulnerability
- SA31094: IBM AIX DNS Cache Poisoning
- SA31137: Blue Coat PacketShaper and iShaper DNS Cache Poisoning
- SA31151: Blue Coat ProxySG DNS Cache Poisoning Vulnerability
- SA31152: Blue Coat Director DNS Cache Poisoning Vulnerability
- SA31153: Blue Coat ProxyRA DNS Cache Poisoning Vulnerability
- SA31197: dnsmasq Denial of Service and DNS Cache Poisoning
- SA31207: Sidewinder and CyberGuard DNS Cache Poisoning
- SA31212: OpenBSD BIND Query Port DNS Cache Poisoning
- SA31213: BlueCat Networks Adonis DNS Cache Poisoning
- SA31221: Citrix NetScaler DNS Cache Poisoning
- SA31326: Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
- SA31354: Astaro Security Gateway DNS Cache Poisoning
- SA31430: Ruby Multiple Vulnerabilities
- SA31447: VitalQIP DNS Cache Poisoning Vulnerability
- SA31451: Yamaha RT Series Routers DNS Cache Poisoning
- SA31482: HP TCP/IP Services for OpenVMS BIND DNS Cache Poisoning
- SA31495: HP Tru64 UNIX BIND Query Port DNS Cache Poisoning
- SA31588: Nortel Business Communications Manager BIND DNS Cache Poisoning
- SA31594: Citrix Access Gateway DNS Cache Poisoning
- SA31742: Astaro Security Gateway DNS Cache Poisoning
- SA31823: Apple iPod Touch Multiple Vulnerabilities
- SA31840: Ingate Firewall and SIParator DNS Cache Poisoning
- SA31882: Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
- SA31900: Apple iPhone Multiple Vulnerabilities
- SA32625: Sun Solaris IP Filter DNS Cache Poisoning
- SA33714: HP MPE/iX DNS Cache Poisoning Vulnerability
- SA33786: HP NonStop Server DNS Cache Poisoning Vulnerability
- SECTRACK ID: 1020437: Windows DNS Service Bugs Let Remote Users Spoof the System
- SECTRACK ID: 1020438: BIND DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020440: Cisco IOS DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020448: Juniper ScreenOS DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020449: Juniper JUNOS DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020548: Blue Coat ProxySG DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020558: Citrix NetScaler DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020560: Adonis DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020561: Secure Computing Sidewinder DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020575: Cisco PIX Firewall Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack
- SECTRACK ID: 1020576: Cisco ASA Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack
- SECTRACK ID: 1020577: Cisco Firewall Service Module Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack
- SECTRACK ID: 1020578: Cisco Content Switching Module Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack
- SECTRACK ID: 1020579: Cisco IOS Predictable Source Port Address Translation May Leave DNS Servers Vulnerable to Recent Cache Poisoning Attack
- SECTRACK ID: 1020651: Dnsmasq DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020653: Ruby 'resolv.rb' DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020702: VitalQIP Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020802: Nortel Business Communications Manager DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SECTRACK ID: 1020804: Citrix Access Gateway DNS Query Port Entropy Weakness Lets Remote Users Spoof the System
- SUSE-SA:2008:033: bind DNS poisoning attack problems
- SUSE-SA:2008:041: openwsman
- SUSE-SR:2008:017: SUSE Security Summary Report
Reported:
Jul 08, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
