CVE-2007-2926

Impact:
Moderate
Public Date:
2007-07-23
Bugzilla:
248851: CVE-2007-2926 bind cryptographically weak query ids

The MITRE CVE dictionary describes this issue as:

ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.

Find out more about CVE-2007-2926 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Updates are available for Red Hat Enterprise Linux 2.1, 3, 4, and 5 to correct this issue:
http://rhn.redhat.com/errata/RHSA-2007-0740.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 4 (bind) RHSA-2007:0740 2007-07-24
Red Hat Enterprise Linux 2.1 (bind) RHSA-2007:0740 2007-07-24
Red Hat Enterprise Linux 5 (bind) RHSA-2007:0740 2007-07-24
Red Hat Enterprise Linux 3 (bind) RHSA-2007:0740 2007-07-24

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.