CVE-2008-1447
Summary
| CVE | CVE-2008-1447 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-07-08 23:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug." |
Risk And Classification
Primary CVSS: v3.1 6.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Problem Types: CWE-331 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | All | All | All |
| Operating System | Cisco | Ios | 12.0 | All | All | All |
| Operating System | Debian | Debian Linux | 4.0 | All | All | All |
| Application | Isc | Bind | 4 | All | All | All |
| Application | Isc | Bind | 8 | All | All | All |
| Application | Isc | Bind | 9.2.9 | All | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | - | - | All | All |
| Operating System | Microsoft | Windows Xp | - | sp3 | All | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | as | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | es | All |
| Operating System | Redhat | Enterprise Linux | 2.1 | All | ws | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | client | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | client_workstation | All |
| Operating System | Redhat | Enterprise Linux | 5.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Juniper ScreenOS DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Support | Status of CVE-2008-1447 - Multiple DNS implementations vulnerable to cache poisoning | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Third Party Advisory |
| CTX117991 - Vulnerability in NetScaler and Access Gateway Enterprise Edition could result in DNS Cache Poisoning - Citrix Knowledge Center | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Red Hat update for dnsmasq - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Tool Signature |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Blue Coat Director DNS Cache Poisoning Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| #239392: Security Vulnerability in the DNS Protocol may lead to DNS Cache Poisoning | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Third Party Advisory |
| APPLE-SA-2008-09-12 iPhone v2.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Ubuntu update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM IZ26672: POTENTIAL SECURITY ISSUE IN BIND CVE-2008-1447 APPLIES TO AIX 6100-01 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Ruby Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Cisco ASA Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| BIND: Cache poisoning — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Astaro Security Gateway DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Departement Natuurkunde - Universiteit Utrecht | af854a3a-2127-422b-91ae-364da2661108 | www.phys.uu.nl | Third Party Advisory |
| FreeBSD update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 13>0 : DoxPara Research | af854a3a-2127-422b-91ae-364da2661108 | www.doxpara.com | Third Party Advisory |
| Invisible Denizen: Kaminsky's DNS Issue Accidentally Leaked? | af854a3a-2127-422b-91ae-364da2661108 | blog.invisibledenizen.org | Technical Description |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| ISC has a new website | Internet Systems Consortium | af854a3a-2127-422b-91ae-364da2661108 | www.isc.org | Third Party Advisory |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Multiple vulnerabilities in Ruby | af854a3a-2127-422b-91ae-364da2661108 | www.ruby-lang.org | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | Broken Link |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1619-1 python-dns | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Novell Netware DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM AIX DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1623-1 dnsmasq | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Tool Signature |
| APPLE-SA-2008-07-31 Security Update 2008-005 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Sidewinder and CyberGuard DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1604-1 bind | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Vulnerability in Access Gateway Standard and Advanced Edition Appliance firmware could result in DNS Cache Poisoning | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Third Party Advisory |
| Cisco IOS Predictable Source Port Address Translation May Leave DNS Servers Vulnerable to Recent Cache Poisoning Attack - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| IBM Corporation Information for VU#800113 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Advisories:rPSA-2008-0231 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | Third Party Advisory |
| Microsoft Windows DNS Spoofing Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| pdnsd maintenance page by Paul Rombouts | af854a3a-2127-422b-91ae-364da2661108 | www.phys.uu.nl | Third Party Advisory |
| www.nominum.com/asset_upload_file741_2661.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.nominum.com | Third Party Advisory |
| Nortel: Technical Support: Nortel Guidance for Multiple Vendor Fixes for BIND/DNS Cache Poison Vulnerability - CVE-2008-1447 | af854a3a-2127-422b-91ae-364da2661108 | support.nortel.com | Third Party Advisory |
| Infoblox NIOS BIND Query Port DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-1605-1 glibc | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| HP TCP/IP Services for OpenVMS BIND DNS Cache Poisoning - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| ISC BIND Query Port DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Slackware update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Cisco Content Switching Module Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| IPCop update for various packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Nortel Business Communications Manager DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| NetBSD update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Ubuntu update for dnsmasq - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| IBM IZ26670: POTENTIAL SECURITY ISSUE IN BIND CVE-2008-1447 APPLIES TO AIX 5300-08 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Third Party Advisory |
| US-CERT Vulnerability Note VU#800113 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| USN-627-1: Dnsmasq vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| FAQ for YAMAHA RT Series / Security | af854a3a-2127-422b-91ae-364da2661108 | www.rtpro.yamaha.co.jp | Third Party Advisory |
| About the security content of iPhone v2.1 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| Debian bind DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Apple iPod Touch Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| OpenBSD BIND Query Port DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Blue Coat ProxySG DNS Cache Poisoning Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Juniper JUNOS DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Ruby 'resolv.rb' DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco Firewall Service Module Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| APPLE-SA-2008-09-15 Mac OS X v10.5.5 and Security Update 2008-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| About the security content of iPod touch v2.1 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| [SECURITY] Fedora 8 Update: bind-9.5.0-28.P1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Sun Solaris DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| F5 Products DNS Cache Poisoning Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| HP-UX update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| '[security bulletin] HPSBOV03226 rev.1 - HP TCP/IP Services for OpenVMS, BIND 9 Resolver, Multiple Re' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Nortel Business Communications Manager BIND DNS Cache Poisoning - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM IZ26671: POTENTIAL SECURITY ISSUE IN BIND CVE-2008-1447 APPLIES TO AIX 6100-00 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Third Party Advisory |
| Broadcom Inc. | Connecting Everything | af854a3a-2127-422b-91ae-364da2661108 | www.bluecoat.com | Third Party Advisory |
| Red Hat update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IPCop 1.4.19 / 1.4.20 released :: IPCop.org :: The bad packets stop here! | af854a3a-2127-422b-91ae-364da2661108 | www.ipcop.org | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Ruby: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Blue Coat PacketShaper and iShaper DNS Cache Poisoning - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (c) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Third Party Advisory, VDB Entry |
| USN-622-1: Bind vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| SUSE update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| OpenBSD 4.2 errata | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| VMSA-2008-0014.3 - VMware | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Third Party Advisory |
| www.caughq.org/exploits/CAU-EX-2008-0003.txt | af854a3a-2127-422b-91ae-364da2661108 | www.caughq.org | Third Party Advisory |
| Advisories:rPSA-2010-0018 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | Third Party Advisory |
| security.freebsd.org/advisories/FreeBSD-SA-08:06.bind.asc | af854a3a-2127-422b-91ae-364da2661108 | security.freebsd.org | Third Party Advisory |
| Debian update for python-dns - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Fedora update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| SecurityTracker.com Archives - BIND DNS Query Port Entropy Weakness Lets Remote Users Spoof the System | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| US-CERT Technical Cyber Security Alert TA08-190B -- Multiple DNS implementations vulnerable to cache poisoning | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Apple iPhone Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Tool Signature |
| Blue Coat ProxyRA DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| HP MPE/iX DNS Cache Poisoning Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Juniper Networks Products DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Infoblox Information for VU#800113 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA08-260A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | Third Party Advisory |
| Secure Computing Sidewinder DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Cisco PIX Firewall Predictable Source Port Address Translation Leaves DNS Servers Vulnerable to Recent Cache Poisoning Attack - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Sun Solaris 10 DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA08-190A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Gentoo Linux Documentation -- VMware Player, Server, Workstation: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Tool Signature |
| Debian -- Security Information -- DSA-1603-1 bind9 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch |
| Windows DNS Service Bugs Let Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| VitalQIP Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Slackware update for dnsmasq - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Dnsmasq DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Yamaha RT Series Routers DNS Cache Poisoning - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Citrix NetScaler DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Cisco Security Advisory: Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Third Party Advisory |
| BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (py) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Third Party Advisory, VDB Entry |
| HP NonStop Server DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Debian update for dnsmasq - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Blue Coat ProxySG DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| rPath update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Nominum CNS and Vantio DNS Cache Poisoning Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM IZ26668: POTENTIAL SECURITY ISSUE IN BIND CVE-2008-1447 APPLIES TO AIX 5300-06 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Third Party Advisory |
| Adonis DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Microsoft Security Bulletin MS08-037 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | Patch, Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| dnsmasq Denial of Service and DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Third Party Advisory |
| An Illustrated Guide to the Kaminsky DNS Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.unixwiz.net | Third Party Advisory |
| Up2Date Announcements: Up2Date 7.202 released | af854a3a-2127-422b-91ae-364da2661108 | up2date.astaro.com | Third Party Advisory |
| www.caughq.org/exploits/CAU-EX-2008-0002.txt | af854a3a-2127-422b-91ae-364da2661108 | www.caughq.org | Third Party Advisory |
| #494401 - ruby1.8: New release (1.8.7-p71) with vulnerabilities fixes - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Third Party Advisory |
| Multiple Vendor DNS Protocol Insufficient Transaction ID Randomization DNS Spoofing Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Nixu Secure Name Server BIND Query Port DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| [security-announce] SUSE Security Announcement: bind (SUSE-SA:2008:033) | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Tool Signature |
| OpenBSD 4.3 errata | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2008:139 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| IBM IZ26669: POTENTIAL SECURITY ISSUE IN BIND CVE-2008-1447 APPLIES TO AIX 5300-07 - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Third Party Advisory |
| SecurityTracker.com Archives - Cisco IOS DNS Query Port Entropy Weakness Lets Remote Users Spoof the System | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Cisco Products DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Debian update for bind9 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| HP Tru64 UNIX BIND Query Port DNS Cache Poisoning - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| BlueCat Networks Adonis DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| [SECURITY] Fedora 9 Update: bind-9.5.0-33.P1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Citrix Access Gateway DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| [Full-disclosure] VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues. | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | Broken Link |
| APPLE-SA-2008-09-09 iPod touch v2.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | Broken Link |
| Citrix NetScaler DNS Cache Poisoning - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-009.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | Third Party Advisory, Vendor Advisory |
| Page not found | Dan Kaminsky's Blog | af854a3a-2127-422b-91ae-364da2661108 | www.doxpara.com | Third Party Advisory |
| BIND 9.4.1-9.4.2 Remote DNS Cache Poisoning Flaw Exploit (meta) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-07-09 | Mark J Cox | http://rhn.redhat.com/errata/RHSA-2008-0533.html |
There are currently no legacy QID mappings associated with this CVE.