CVE-2007-2926
published 2007-07-24CVE-2007-2926: ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
13.09%
95.9th percentile
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.4.1-P1-1 (bookworm) | bind9 1:9.4.1-P1-1 (bookworm) |
| isc | bind | <= 8.4.7 | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-07:07.bind: Predictable query ids in named(8)
bsd_advisories·2007-08-01·CVSS 4.3
CVE-2007-2926 [MEDIUM] FreeBSD-SA-07:07.bind: Predictable query ids in named(8)
FreeBSD-SA-07:07.bind Security Advisory
The FreeBSD Project
Topic: Predictable query ids in named(8)
Category: contrib
Module: bind
Announced: 2007-08-01
Credits: Amit Klein
Affects: FreeBSD 5.3 and later.
Corrected: 2007-07-25 08:23:08 UTC (RELENG_6, 6.2-STABLE)
2007-08-01 20:44:58 UTC (RELENG_6_2, 6.2-RELEASE-p7)
2007-08-01 20:45:49 UTC (RELENG_6_1, 6.1-RELEASE-p19)
2007-07-25 08:24:40 UTC (RELENG_5, 5.5-STABLE)
2007-08-01 20:48:19 UTC (RELENG_5_5, 5.5-RELEASE-p15)
CVE Name: CVE-2007-2926
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Nam
Ubuntu
Bind vulnerability
vendor_ubuntu·2007-07-25
CVE-2007-2926 Bind vulnerability
Title: Bind vulnerability
Summary: Bind vulnerability
A flaw was discovered in Bind's sequence number generator. A remote
attacker could calculate future sequence numbers and send forged DNS
query responses. This could lead to client connections being directed
to attacker-controlled hosts, resulting in credential theft and other
attacks.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
bind cryptographically weak query ids
vendor_redhat·2007-07-23·CVSS 4.3
CVE-2007-2926 [MEDIUM] bind cryptographically weak query ids
bind cryptographically weak query ids
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
Debian
CVE-2007-2926: bind9 - ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation...
vendor_debian·2007·CVSS 4.3
CVE-2007-2926 [MEDIUM] CVE-2007-2926: bind9 - ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation...
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
Scope: local
bookworm: resolved (fixed in 1:9.4.1-P1-1)
bullseye: resolved (fixed in 1:9.4.1-P1-1)
forky: resolved (fixed in 1:9.4.1-P1-1)
sid: resolved (fixed in 1:9.4.1-P1-1)
trixie: resolved (fixed in 1:9.4.1-P1-1)
Red Hat
CVE-2007-2930: The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8
vendor_redhat·CVSS 4.3
CVE-2007-2930 [MEDIUM] CVE-2007-2930: The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.
Statement: Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
GHSA
GHSA-f6h8-pjrf-562j: ISC BIND 9 through 9
ghsa_unreviewed·2022-05-03
CVE-2007-2926 [MEDIUM] GHSA-f6h8-pjrf-562j: ISC BIND 9 through 9
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
GHSA
GHSA-8m5r-mf8j-3hfx: The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-2930 [MEDIUM] GHSA-8m5r-mf8j-3hfx: The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.
OSV
CVE-2007-2926: ISC BIND 9 through 9
osv·2007-07-24·CVSS 4.3
CVE-2007-2926 [MEDIUM] CVE-2007-2926: ISC BIND 9 through 9
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
No detection rules found.
ftp://aix.software.ibm.com/aix/efixes/security/READMEftp://patches.sgi.com/support/free/security/advisories/20070801-01-P.aschttp://docs.info.apple.com/article.html?artnum=307041http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01123426http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01154600http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01174368http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://secunia.com/advisories/26148http://secunia.com/advisories/26152http://secunia.com/advisories/26160http://secunia.com/advisories/26180http://secunia.com/advisories/26195http://secunia.com/advisories/26217http://secunia.com/advisories/26227http://secunia.com/advisories/26231http://secunia.com/advisories/26236http://secunia.com/advisories/26261http://secunia.com/advisories/26308http://secunia.com/advisories/26330http://secunia.com/advisories/26509http://secunia.com/advisories/26515http://secunia.com/advisories/26531http://secunia.com/advisories/26605http://secunia.com/advisories/26607http://secunia.com/advisories/26847http://secunia.com/advisories/26925http://secunia.com/advisories/27643http://security.freebsd.org/advisories/FreeBSD-SA-07:07.bind.aschttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103018-1http://support.avaya.com/elmodocs2/security/ASA-2007-389.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=623903http://www-1.ibm.com/support/search.wss?rs=0&q=IZ02218&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IZ02219&apar=onlyhttp://www.debian.org/security/2007/dsa-1341http://www.gentoo.org/security/en/glsa/glsa-200708-13.xmlhttp://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.kb.cert.org/vuls/id/252735http://www.mandriva.com/security/advisories?name=MDKSA-2007:149http://www.novell.com/linux/security/advisories/2007_47_bind.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2007.022.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0740.htmlhttp://www.securiteam.com/securitynews/5VP0L0UM0A.htmlhttp://www.securityfocus.com/archive/1/474516/100/0/threadedhttp://www.securityfocus.com/archive/1/474545/100/0/threadedhttp://www.securityfocus.com/archive/1/474808/100/0/threadedhttp://www.securityfocus.com/archive/1/474856/100/0/threadedhttp://www.securityfocus.com/bid/25037http://www.securityfocus.com/bid/26444http://www.securitytracker.com/id?1018442http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.521385http://www.trusteer.com/docs/bind9dns.htmlhttp://www.trusteer.com/docs/bind9dns_s.htmlhttp://www.trustix.org/errata/2007/0023/http://www.ubuntu.com/usn/usn-491-1http://www.us-cert.gov/cas/techalerts/TA07-319A.htmlhttp://www.vupen.com/english/advisories/2007/2627http://www.vupen.com/english/advisories/2007/2662http://www.vupen.com/english/advisories/2007/2782http://www.vupen.com/english/advisories/2007/2914http://www.vupen.com/english/advisories/2007/2932http://www.vupen.com/english/advisories/2007/3242http://www.vupen.com/english/advisories/2007/3868https://exchange.xforce.ibmcloud.com/vulnerabilities/35575https://issues.rpath.com/browse/RPL-1587https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10293https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2226ftp://aix.software.ibm.com/aix/efixes/security/READMEftp://patches.sgi.com/support/free/security/advisories/20070801-01-P.aschttp://docs.info.apple.com/article.html?artnum=307041http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01123426http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01154600http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01174368http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://secunia.com/advisories/26148http://secunia.com/advisories/26152http://secunia.com/advisories/26160http://secunia.com/advisories/26180http://secunia.com/advisories/26195http://secunia.com/advisories/26217http://secunia.com/advisories/26227http://secunia.com/advisories/26231http://secunia.com/advisories/26236http://secunia.com/advisories/26261http://secunia.com/advisories/26308http://secunia.com/advisories/26330http://secunia.com/advisories/26509http://secunia.com/advisories/26515http://secunia.com/advisories/26531http://secunia.com/advisories/26605http://secunia.com/advisories/26607http://secunia.com/advisories/26847http://secunia.com/advisories/26925http://secunia.com/advisories/27643http://security.freebsd.org/advisories/FreeBSD-SA-07:07.bind.aschttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103018-1http://support.avaya.com/elmodocs2/security/ASA-2007-389.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=623903http://www-1.ibm.com/support/search.wss?rs=0&q=IZ02218&apar=only
+ 34 more references
2007-07-24
Published