CVE-2007-2926

NameCVE-2007-2926
DescriptionISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1341-2
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bind9 (PTS)stretch (security), stretch1:9.10.3.dfsg.P4-12.3+deb9u6fixed
buster, buster (security)1:9.11.5.P4+dfsg-5.1+deb10u1fixed
bullseye, sid1:9.16.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bind9sourcesarge1:9.2.4-1sarge3DSA-1341-2
bind9sourceetch1:9.3.4-2etch1DSA-1341-2
bind9source(unstable)1:9.4.1-P1-1

Search for package or bug name: Reporting problems