CVE-2007-3377: Medium severity Nlnet Labs Net Dns vulnerability
Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3377?
CVE-2007-3377 is classified as a medium severity vulnerability due to its potential to allow remote DNS response spoofing.
How do I fix CVE-2007-3377?
To fix CVE-2007-3377, upgrade to a version of Net::DNS that is 0.60 or later to eliminate the predictable sequence ID issue.
What versions of Net::DNS are affected by CVE-2007-3377?
CVE-2007-3377 affects multiple versions of Net::DNS prior to 0.60, including 0.48_03, 0.46, and others listed in the advisory.
Can CVE-2007-3377 be exploited remotely?
Yes, CVE-2007-3377 can be exploited remotely, allowing attackers to spoof DNS responses by leveraging the predictable sequence IDs.
Is there a known workaround for CVE-2007-3377 if I cannot update?
There are no effective workarounds for CVE-2007-3377, and the recommended solution is to upgrade to a patched version.