CVE-2008-5133
published 2008-11-18CVE-2008-5133: ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly…
PriorityP429medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.86%
76.8th percentile
ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass an intended CVE-2008-1447 protection mechanism and spoof the responses to DNS queries sent by named.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products | — | — |
| sun | opensolaris | <= snv_95 | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
| sun | opensolaris | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qxw9-5pqg-5rq6: ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, im
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2008-5133 [MEDIUM] GHSA-qxw9-5pqg-5rq6: ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, im
ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass an intended CVE-2008-1447 protection mechanism and spoof the responses to DNS queries sent by named.
Cisco
Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks
vendor_cisco·2008-07-08·CVSS 6.4
CVE-2008-1447 [MEDIUM] CWE-310 Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks
Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks
Multiple Cisco products are vulnerable to DNS cache poisoning attacks
due to their use of insufficiently randomized DNS transaction IDs and UDP
source ports in the DNS queries that they produce, which may allow an attacker
to more easily forge DNS answers that can poison DNS caches.
To exploit this vulnerability an attacker must be able to cause a
vulnerable DNS server to perform recursive DNS queries. Therefore, DNS servers
that are only authoritative, or servers where recursion is not allowed, are not
affected.
Cisco has released software updates that address these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080708-dns.
This securi
Cisco
Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks
vendor_cisco
CVE-2008-5133 Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks
CVE-2008-5133: Multiple Cisco Products Vulnerable to DNS Cache Poisoning Attacks
Multiple Cisco products are vulnerable to DNS cache poisoning attacks due to their use of insufficiently randomized DNS transaction IDs and UDP source ports in the DNS queries that they produce, which may allow an attacker to more easily forge DNS answers that can poison DNS caches. To exploit this vulnerability an attacker must be able to cause a vulnerable DNS server to perform recursive DNS queries. Therefore, DNS servers that are only authoritative, or servers where recursion is not allowed, are not affected. Cisco has released software updates that address these vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080708-dns .
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/32625http://sunsolve.sun.com/search/document.do?assetkey=1-26-245206-1http://www.vupen.com/english/advisories/2008/3129https://exchange.xforce.ibmcloud.com/vulnerabilities/46721http://secunia.com/advisories/32625http://sunsolve.sun.com/search/document.do?assetkey=1-26-245206-1http://www.vupen.com/english/advisories/2008/3129https://exchange.xforce.ibmcloud.com/vulnerabilities/46721
2008-11-18
Published