← Back

CVE-2008-4099

nvd nist
Published: Sep 18, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

Affected (10)

Products: Debian: Python Dns
1 product
Python Dns
Configuration A
10 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Debian
Up to 2.3.1-3
Version 2.3.0-1
Version 2.3.0-2
Version 2.3.0-3
Version 2.3.0-4
Version 2.3.0-5.1
Version 2.3.0-5
Version 2.3.0-6
Version 2.3.1-1
Version 2.3.1-2
Running on/withPlatform Versions
Debian
Linux
Version unknown unknown

Related CWEs

Timeline

No history available yet.