LWN.net Logo

c-ares: DNS cache poisoning

Package(s):c-ares CVE #(s):CVE-2007-3152 CVE-2007-3153
Created:June 28, 2007 Updated:July 3, 2007
Description: Versions of the c-ares DNS library below 1.4.0 are vulnerable to application DNS cache poisoning caused by a predictable DNS "Transaction ID" field in a DNS query.
Alerts:
Fedora FEDORA-2007-0724 2007-06-27

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds