CVE-2007-2926: Medium severity ISC BIND vulnerability
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2926?
CVE-2007-2926 is rated as a critical vulnerability due to its potential for DNS cache poisoning.
How do I fix CVE-2007-2926?
To fix CVE-2007-2926, upgrade to BIND version 9.5.1 or later, which addresses the weak random number generator issue.
What flaw does CVE-2007-2926 exploit?
CVE-2007-2926 exploits the weak random number generator used in the creation of DNS query IDs, allowing attackers to predict them.
Which versions of BIND are affected by CVE-2007-2926?
CVE-2007-2926 affects BIND versions 9.0 through 9.5.0.
What type of attack does CVE-2007-2926 enable?
CVE-2007-2926 enables remote attackers to perform DNS cache poisoning attacks.