CVE-2007-2926

NameCVE-2007-2926
DescriptionISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1341-2
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bind9 (PTS)jessie (security), jessie1:9.9.5.dfsg-9+deb8u15fixed
stretch (security), stretch1:9.10.3.dfsg.P4-12.3+deb9u4fixed
buster1:9.11.3+dfsg-2fixed
sid1:9.11.4+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bind9source(unstable)1:9.4.1-P1-1medium
bind9sourceetch1:9.3.4-2etch1mediumDSA-1341-2
bind9sourcesarge1:9.2.4-1sarge3mediumDSA-1341-2

Search for package or bug name: Reporting problems