CVE-2007-2926

NameCVE-2007-2926
DescriptionISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1341-2
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bind9 (PTS)wheezy1:9.8.4.dfsg.P1-6+nmu2+deb7u10fixed
wheezy (security)1:9.8.4.dfsg.P1-6+nmu2+deb7u18fixed
jessie1:9.9.5.dfsg-9+deb8u12fixed
jessie (security)1:9.9.5.dfsg-9+deb8u13fixed
stretch1:9.10.3.dfsg.P4-12.3+deb9u3fixed
stretch (security)1:9.10.3.dfsg.P4-12.3+deb9u2fixed
buster1:9.10.3.dfsg.P4-12.6fixed
sid1:9.10.6+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bind9source(unstable)1:9.4.1-P1-1medium
bind9sourceetch1:9.3.4-2etch1mediumDSA-1341-2
bind9sourcesarge1:9.2.4-1sarge3mediumDSA-1341-2

Search for package or bug name: Reporting problems