CVE-2008-4392
Estado: ModificadaMedia (6.4)—
dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.69%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-362
Referencias
- http://secunia.com/advisories/33855
- http://www.securityfocus.com/bid/33818
- http://www.your.org/dnscache/
- http://www.your.org/dnscache/djbdns.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48807
- http://secunia.com/advisories/33855
- http://www.securityfocus.com/bid/33818
- http://www.your.org/dnscache/
- http://www.your.org/dnscache/djbdns.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48807
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4392",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-02-19T16:30:00.327",
"references": [
{
"url": "http://secunia.com/advisories/33855",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/33818",
"source": "cret@cert.org"
},
{
"url": "http://www.your.org/dnscache/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.your.org/dnscache/djbdns.pdf",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48807",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/33855",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/33818",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.your.org/dnscache/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.your.org/dnscache/djbdns.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48807",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query."
},
{
"lang": "es",
"value": "dnscache en Daniel J. Bernstein djbdns v1.05 no previene peticiones DNS de salida idénticas simultáneas, lo cual hace más sencillo a atacantes remotos envenenar respuestas DNS, como lo demostrado por un registro A envenenado en la sección \"Additional\" de una respuesta a un petición \"Start of Authority\" (SOA)."
}
],
"lastModified": "2026-06-16T22:57:43.650",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:d.j.bernstein:djbdns:1.05:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC196644-7220-46EF-92CF-87F9BD45AEF5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}