CVE-2008-1447

The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
microsoftCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
iscbind
9.2.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
adns
bookworm
1.6.0-2
fixed
bullseye
1.6.0-2
fixed
sid
1.6.1-1
fixed
trixie
1.6.1-1
fixed
bind9
bullseye
1:9.16.50-1~deb11u2
fixed
bullseye (security)
1:9.16.50-1~deb11u1
fixed
bookworm
1:9.18.28-1~deb12u2
fixed
bookworm (security)
1:9.18.28-1~deb12u2
fixed
sid
1:9.20.2-1
fixed
trixie
1:9.20.2-1
fixed
dnsmasq
bullseye
2.85-1
fixed
bookworm
2.89-1
fixed
sid
2.90-4
fixed
trixie
2.90-4
fixed
dnspython
bullseye
2.0.0-1
fixed
bookworm
2.3.0-1
fixed
sid
2.6.1-1
fixed
trixie
2.6.1-1
fixed
libnet-dns-perl
bullseye
1.29-1
fixed
bookworm
1.36-1
fixed
sid
1.47-1
fixed
trixie
1.47-1
fixed
refpolicy
bullseye
2:2.20210203-7
fixed
bookworm
2:2.20221101-9
fixed
sid
2:2.20241013-1
fixed
trixie
2:2.20241013-1
fixed
udns
bookworm
0.4-1
fixed
bullseye
0.4-1
fixed
sid
0.6-1
fixed
trixie
0.6-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bind9
karmic
Fixed 1:9.5.0.dfsg.P1-2~build1
released
jaunty
Fixed 1:9.5.0.dfsg.P1-2~build1
released
intrepid
Fixed 1:9.5.0.dfsg.P1-2~build1
released
hardy
Fixed 1:9.4.2-10ubuntu0.1
released
gutsy
Fixed 1:9.4.1-P1-3ubuntu2
released
feisty
Fixed 1:9.3.4-2ubuntu2.3
released
dapper
Fixed 1:9.3.2-2ubuntu1.5
released
dnsmasq
karmic
Fixed 2.43-1ubuntu1
released
jaunty
Fixed 2.43-1ubuntu1
released
intrepid
Fixed 2.43-1ubuntu1
released
hardy
Fixed 2.41-2ubuntu2.1
released
gutsy
ignored
feisty
ignored
dapper
ignored
eglibc
karmic
not-affected
jaunty
dne
intrepid
dne
hardy
dne
gutsy
dne
feisty
dne
dapper
dne
glibc
karmic
dne
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
gutsy
ignored
feisty
ignored
dapper
not-affected
python-dns
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 2.3.1-2ubuntu0.2
released
gutsy
Fixed 2.3.1-1ubuntu0.2
released
feisty
Fixed 2.3.0-5.1ubuntu2.2
released
dapper
Fixed 2.3.0-5ubuntu1.2
released
References