CVE-2008-4392
Publication date 19 February 2009
Last updated 24 July 2024
Ubuntu priority
Description
dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| djbdns | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Ignored end of standard support, was needed | |
| 14.04 LTS trusty | Not in release | |
Notes
sbeattie
debian attempted to mitigate the issue somewhat in 1:1.05-6 (lucid and newer) but the issue still stands