oss-sec mailing list archives
Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb)
From: "Steven M. Christey" <coley () linus mitre org>
Date: Thu, 4 Sep 2008 12:01:04 -0400 (EDT)
On Wed, 3 Sep 2008, Jan Lieskovsky wrote:
could you please allocate an another CVE id for the DNS spoofing vulnerability in Ruby resolv.rb code. http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/ (part DNS spoofing vulnerability in resolv.rb) ...
The transaction IDs are assigned in sequential (n+1 order) and the source ports are always the same.
Use CVE-2008-3905, to be filled in soon. We're treating this as a distinct issue because this is *REALLY* bad randomness within a particular implementation, besides the inherent limitation of DNS when source ports are fixed. - Steve
Current thread:
- CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Jan Lieskovsky (Sep 03)
- Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Steven M. Christey (Sep 04)
- Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Tomas Hoger (Sep 11)
- Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Steven M. Christey (Sep 15)
- Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Tomas Hoger (Sep 11)
- Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) Steven M. Christey (Sep 04)
