>> ISC BIND DNS Query ID Generation Weakness Cache Poisoning Vulnerability
Title : ISC BIND DNS Query ID Generation Weakness Cache Poisoning Vulnerability VUPEN ID : VUPEN/ADV-2007-2627 CVE ID : CVE-2007-2926
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-24
Technical Description
A vulnerability has been identified in ISC BIND, which could be exploited by attackers to gain knowledge of sensitive information and poison a DNS cache. This issue is caused by an error within the DNS query ID generation code when answering questions as a resolver or when sending NOTIFYs to slave name servers, which could allow attackers to potentially guess the next query ID and perform cache poisoning.