CVE-2007-3377

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2007
Last modified:
09/04/2025

Description

Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nlnet_labs:net_dns:0.14:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.20:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.21:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.22:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.23:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.24:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.25:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.26:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.27:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.28:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.29:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.30:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.31:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.32:*:*:*:*:*:*:*
cpe:2.3:a:nlnet_labs:net_dns:0.33:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools