|
Message-ID: <Pine.GSO.4.51.0809152058040.6953@faron.mitre.org> Date: Mon, 15 Sep 2008 20:59:40 -0400 (EDT) From: "Steven M. Christey" <coley@...us.mitre.org> To: oss-security@...ts.openwall.com cc: coley@...us.mitre.org Subject: Re: CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb) On Thu, 11 Sep 2008, Tomas Hoger wrote: > > We're treating this as a distinct issue because this is *REALLY* bad > > randomness within a particular implementation, besides the inherent > > limitation of DNS when source ports are fixed. > > Applying this rule, separate id should probably be used for PyDNS [1] > [2] and adns [3] as well, at they both suffer from the similar flaws - > use predictable transactions ids and source port. CVE-2008-4099 - PyDNS CVE-2008-4100 - adns - Steve
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.