6.4

CVE-2008-4100

GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.  NOTE: the vendor reports that this is intended behavior and is compatible with the product's intended role in a trusted environment.

Data is provided by the National Vulnerability Database (NVD)
GnuAdns Version <= 1.4
GnuAdns Version0.1
GnuAdns Version0.2
GnuAdns Version0.3
GnuAdns Version0.4
GnuAdns Version0.5
GnuAdns Version0.6
GnuAdns Version0.7
GnuAdns Version0.8
GnuAdns Version0.9
GnuAdns Version1.0
GnuAdns Version1.1
GnuAdns Version1.2
GnuAdns Version1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.5% 0.63
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:N/I:P/A:P