CVE-2008-3905

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
04/09/2008
Last modified:
09/04/2025

Description

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* 1.8.5 (including)
cpe:2.3:a:ruby-lang:ruby:*:p286:*:*:*:*:*:* 1.8.6 (including)
cpe:2.3:a:ruby-lang:ruby:*:p71:*:*:*:*:*:* 1.8.7 (including)
cpe:2.3:a:ruby-lang:ruby:*:r18423:*:*:*:*:*:* 1.9 (including)
cpe:2.3:a:ruby-lang:ruby:1.6:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p110:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p111:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p114:*:*:*:*:*:*


References to Advisories, Solutions, and Tools