[FREEBSD:959D384D-6B59-11DD-9D79-001FC61C2A55] ruby -- DNS spoofing vulnerability
Severity
Medium
Affected Packages
1
CVEs
1
The official ruby site reports:
resolv.rb allow remote attackers to spoof DNS answers. This risk
can be reduced by randomness of DNS transaction IDs and source
ports.
Package | Affected Version |
---|---|
pkg:freebsd/ruby | < 1.8.6.111_5,1 |
- ID
- FREEBSD:959D384D-6B59-11DD-9D79-001FC61C2A55
- Severity
- medium
- Severity from
- CVE-2008-1447
- URL
- http://vuxml.freebsd.org/freebsd/959d384d-6b59-11dd-9d79-001fc61c2a55.html
- Published
-
2008-08-08T00:00:00
(16 years ago) - Modified
-
2008-08-16T00:00:00
(16 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
-
- CISCO-SA-20080708-DNS
- ELSA-2008-0533
- ELSA-2008-0789
- FEDORA-2008-6256
- FEDORA-2008-6281
- FEDORA-2008-8736
- FEDORA-2008-8738
- FEDORA-2009-0350
- FEDORA-2009-1069
- FREEBSD:655EE1EC-511B-11DD-80BA-000BCDF0A03B
- GLSA-200807-08
- GLSA-200809-02
- GLSA-200812-17
- GLSA-200901-03
- GLSA-201209-25
- SSA:2008-191-02
- SSA:2008-205-01
- SSA:2008-334-01
- USN-622-1
- USN-627-1
- VU:800113
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/ruby | ruby | < 1.8.6.111_5,1 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |