Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby 'resolv.rb' Predictable Transaction ID and Source Port DNS欺骗漏洞
Vulnerability Description
Ruby,一种为简单快捷面向对象编程(面向对象程序设计)而创的脚本语言,由日本人松本行弘开发,遵守GPL协议和Ruby License。 Ruby 1.8.5以及之前的版本,1.8.6-p287之前的1.8.6版本,1.8.7-p72之前的1.8.7版本和1.9 r18423以及之前的版本中的resolv.rb使用连续的transaction IDs和对DNS请求的不变源端口,这会使远程攻击者更易于骗取DNS响应。
CVSS Information
N/A
Vulnerability Type
N/A