|
|
| |
|
| |
c-ares: DNS cache poisoning
| Package(s): | c-ares |
CVE #(s): | CVE-2007-3152
CVE-2007-3153
|
| Created: | June 28, 2007 |
Updated: | July 3, 2007 |
| Description: |
Versions of the c-ares DNS library below 1.4.0 are vulnerable to application
DNS cache poisoning caused by a predictable DNS "Transaction ID" field in a
DNS query. |
| Alerts: |
|
( Log in to post comments)
|
|
|