National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2007-2930 Detail

Description

The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.

Source:  MITRE      Last Modified:  09/11/2007

Quick Info

CVE Dictionary Entry:
CVE-2007-2930
Original release date:
09/11/2007
Last revised:
10/10/2017
Source:
US-CERT/NIST

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score:
4.3 MEDIUM
Vector:
(AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore:
2.9
Exploitability Subscore:
8.6
CVSS Version 2 Metrics:
Access Vector:
Network exploitable
Access Complexity:
Medium
Authentication:
Not required to exploit
Impact Type:
Allows unauthorized modification

Vendor Statements (disclaimer)

Official Statement from Red Hat (09/12/2007)

Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource Type Source Name
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01283837 External Source HP SSRT071461
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103063-1 External Source SUNALERT 103063
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200859-1 External Source SUNALERT 200859
http://support.avaya.com/elmodocs2/security/ASA-2007-448.htm External Source CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2007-448.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=653968 External Source CONFIRM http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=653968
http://www.ciac.org/ciac/bulletins/r-333.shtml Patch External Source CIAC R-333
http://www.isc.org/index.pl?/sw/bind/bind8-eol.php Patch External Source CONFIRM http://www.isc.org/index.pl?/sw/bind/bind8-eol.php
http://www.kb.cert.org/vuls/id/927905 Patch; US Government Resource External Source CERT-VN VU#927905
http://www.securityfocus.com/archive/1/archive/1/477870/100/100/threaded External Source BUGTRAQ 20070827 BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer)
http://www.securityfocus.com/archive/1/archive/1/481424/100/0/threaded External Source BUGTRAQ 20071001 Re: BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer)
http://www.securityfocus.com/archive/1/archive/1/481659/100/0/threaded External Source BUGTRAQ 20071006 Re: BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer)
http://www.securityfocus.com/bid/25459 External Source BID 25459
http://www.securitytracker.com/id?1018615 External Source SECTRACK 1018615
http://www.trusteer.com/docs/bind8dns.html External Source MISC http://www.trusteer.com/docs/bind8dns.html
http://www.vupen.com/english/advisories/2007/2991 External Source VUPEN ADV-2007-2991
http://www.vupen.com/english/advisories/2007/3192 External Source VUPEN ADV-2007-3192
http://www.vupen.com/english/advisories/2007/3639 External Source VUPEN ADV-2007-3639
http://www.vupen.com/english/advisories/2007/3668 External Source VUPEN ADV-2007-3668
http://www.vupen.com/english/advisories/2007/3936 External Source VUPEN ADV-2007-3936
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/43/022954-01.pdf External Source CONFIRM http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/43/022954-01.pdf
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3975 External Source CONFIRM http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3975
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2154 External Source OVAL oval:org.mitre.oval:def:2154

References to Check Content

Identifier:
oval:org.mitre.oval:def:2154
Check System:
http://oval.mitre.org/XMLSchema/oval-definitions-5
Hyperlink:
http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:2154

Technical Details

Vulnerability Type (View All)

Vulnerable software and versions Switch to CPE 2.2

Configuration 1
OR
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*    versions up to (including) 8.4.7

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History 2 change records found - show changes