CVE-2008-4100: Medium severity gnu adns vulnerability
GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: the vendor reports that this is intended behavior and is compatible with the product's intended role in a trusted environment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4100?
CVE-2008-4100 is classified as a medium severity vulnerability due to its potential to allow DNS response spoofing.
How do I fix CVE-2008-4100?
To mitigate CVE-2008-4100, consider upgrading to a version of GNU adns later than 1.4 which addresses this issue.
What versions of GNU adns are affected by CVE-2008-4100?
CVE-2008-4100 affects GNU adns versions up to and including 1.4.
How does CVE-2008-4100 exploit DNS requests?
CVE-2008-4100 allows attackers to spoof DNS responses by using a fixed source port and sequential transaction IDs in DNS requests.
Is CVE-2008-4100 a known vulnerability?
Yes, CVE-2008-4100 is a documented vulnerability that has been acknowledged by the GNU adns vendor.