Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-4883

Опубликовано: 28 нояб. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lwip_project:lwip:*:*:*:*:*:*:*:*
Версия до 1.4.1 (включая)

EPSS

Процентиль: 30%
0.00114
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-345

Связанные уязвимости

ubuntu
около 11 лет назад

resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

debian
около 11 лет назад

resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in ...

github
больше 3 лет назад

resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

EPSS

Процентиль: 30%
0.00114
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-345