← Back

CVE-2008-3630

nvd nist
Published: Sep 11, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

Affected (1)

Products: Apple: Bonjour
1 product
Bonjour
Configuration A
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4 unknown
Running on/withPlatform Versions
Microsoft
Windows Nt
Version xp sp3
Microsoft
Windows 2000
All versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Xp
All versions

References (12)

Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.