Description
mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/31822
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2990
Patch vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce//2008/Sep/msg00002.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1020844
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2524
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31093
Scores
EPSS
0.0159
EPSS Percentile
73.2%
Details
Status
published
Products (1)
apple/bonjour
1.0.4 unknown
Published
Sep 11, 2008
Tracked Since
Feb 18, 2026