Back to search
CVE-2008-0087
Published: Apr 8, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
TA08-099A
third-party-advisory
x_refsource_CERT
SSRT080048
vendor-advisory
x_refsource_HP
MS08-020
vendor-advisory
x_refsource_MS
29696
third-party-advisory
x_refsource_SECUNIA
HPSBST02329
vendor-advisory
x_refsource_HP
http://www.trusteer.com/docs/windowsresolver.html
x_refsource_MISC
1019802
vdb-entry
x_refsource_SECTRACK
oval:org.mitre.oval:def:5314
vdb-entry
signature
x_refsource_OVAL
ADV-2008-1144
vdb-entry
x_refsource_VUPEN
20080408 Microsoft Windows DNS Stub Resolver Cache Poisoning (MS08-020)
mailing-list
x_refsource_BUGTRAQ
28553
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now