Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3905 (Ruby)

BugsAlert Home > CVE-2008-3905 (Ruby)
 
 

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3905

Learn more about CVE-2008-3905 (Ruby)
 
Tags: cve-2008-3905 ruby

Related Items

      Breaking News! Iran Invaded! Well?maybe

      WallCity-Server Shoutcast Admin Panel Multiple Vulnerabilities

      CVE-2008-1369 (Solaris)

      MS08-017 - Critical: Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (933103)

      FrSIRT - XEmacs Fast-lock Files Processing Code Execution Vulnerability

      AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability

      MS08-010 - Critical: Cumulative Security Update for Internet Explorer (944533) - Version:1.1

 

Pixel