← Back

CVE-2008-3905

nvd nist
Published: Sep 4, 2008Modified: Apr 23, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

Affected (27)

Products: Ruby Lang: Ruby
1 product
Ruby
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
Up to 1.8.5
Up to 1.8.6
Up to 1.8.7
Up to 1.9
Version 1.6.8
Version 1.6
Version 1.8.0
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.6
Version 1.8.6 p110
Version 1.8.6 p111
Version 1.8.6 p114
Version 1.8.6 p230
Version 1.8.6 p36
Version 1.8.6 preview1
Version 1.8.6 preview2
Version 1.8.6 preview3
Version 1.8.7
Version 1.8.7 p17
Version 1.8.7 p22
Version 1.8.7 preview1
Version 1.8.7 preview2
Version 1.8.7 preview3
Version 1.8.7 preview4

References (48)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.