CVE-2008-4392

djbdns 1.05 - DNS Response Spoofing via Simultaneous Identical Outbound Queries

Title source: llm
STIX 2.1

Description

dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
http://www.your.org/dnscache/djbdns.pdf
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/48807
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33855
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33818
Patch, Vendor Advisory x_refsource_misc
http://www.your.org/dnscache/

Scores

EPSS 0.0169
EPSS Percentile 74.2%

Details

CWE
CWE-362
Status published
Products (1)
d.j.bernstein/djbdns 1.05
Published Feb 19, 2009
Tracked Since Feb 18, 2026