CVE-2008-4126
Summary
| CVE | CVE-2008-4126 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-18 17:59:33 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4099. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Debian | Linux | unknown | unknown | etch | All |
| Application | Debian | Python-dns | 2.3.0-1 | All | All | All |
| Application | Debian | Python-dns | 2.3.0-2 | All | All | All |
| Application | Debian | Python-dns | 2.3.0-3 | All | All | All |
| Application | Debian | Python-dns | 2.3.0-4 | All | All | All |
| Application | Debian | Python-dns | 2.3.0-5 | All | All | All |
| Application | Debian | Python-dns | 2.3.0-5.1 | All | All | All |
| Application | Debian | Python-dns | 2.3.0-6 | All | All | All |
| Application | Debian | Python-dns | 2.3.1-1 | All | All | All |
| Application | Debian | Python-dns | 2.3.1-2 | All | All | All |
| Application | Debian | Python-dns | 2.3.1-3 | All | All | All |
| Application | Debian | Python-dns | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | packages.debian.org | |
| oss-security - Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| #490217 - python-dns vulnerable to CVE-2008-1447 DNS source port guessable - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| oss-security - Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.