CVE-2008-3630

Apple Bonjour <1.0.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31822
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2990
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020844
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2524
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31093

Scores

EPSS 0.0159
EPSS Percentile 73.2%

Details

Status published
Products (1)
apple/bonjour 1.0.4 unknown
Published Sep 11, 2008
Tracked Since Feb 18, 2026