CVE-2008-3630
Summary
| CVE | CVE-2008-3630 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-11 01:13:09 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Bonjour | 1.0.4 | unknown | windows | All |
| Operating System | Microsoft | Windows-nt | xp | sp3 | All | All |
| Operating System | Microsoft | Windows 2000 | - | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | - | All | All | All |
| Operating System | Microsoft | Windows Vista | - | All | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| APPLE-SA-2009-09-09 Bonjour for Windows 1.0.5 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch |
| About the security content of Bonjour for Windows 1.0.5 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Apple Bonjour for Windows mDNSResponder Remote Forged DNS Response Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apple Bonjour for Windows mDNSResponder Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apple Bonjour for Windows DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.