« Volver al listado

CVE-2007-3152

Estado: ModificadaAlta (7.5)—

c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3152",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-11T22:30:00.000",
  "references": [
    {
      "url": "http://cool.haxx.se/cvs.cgi/curl/ares/CHANGES?rev=HEAD&content-type=text/vnd.viewcvs-markup",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37171",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25579",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24386",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34979",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://cool.haxx.se/cvs.cgi/curl/ares/CHANGES?rev=HEAD&content-type=text/vnd.viewcvs-markup",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/37171",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25579",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24386",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34979",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value."
    },
    {
      "lang": "es",
      "value": "c-ares anterior a 1.4.0 utiliza un germen para  el generador de númers aleatorios para el campo DNS Transaction ID, el cual podría permitir a atacantes remotos suplantar la respuesta DNS a adivinando el valor del campo."
    }
  ],
  "lastModified": "2026-06-16T22:41:10.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:daniel_stenberg:c-ares:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA7FC9B2-3354-4431-8E6F-3F2752614C04"
            },
            {
              "criteria": "cpe:2.3:a:daniel_stenberg:c-ares:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C514051-90BC-448C-ACE3-EA6C9D0D9351"
            },
            {
              "criteria": "cpe:2.3:a:daniel_stenberg:c-ares:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77EAA046-EA1B-4EA2-9A20-C1E3355988FD"
            },
            {
              "criteria": "cpe:2.3:a:daniel_stenberg:c-ares:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CEE2934-84C0-4EC5-89E4-1B406F1A6BA2"
            },
            {
              "criteria": "cpe:2.3:a:daniel_stenberg:c-ares:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50647B2B-3C8B-4862-A246-6FE25FD40018"
            },
            {
              "criteria": "cpe:2.3:a:daniel_stenberg:c-ares:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE6851AE-DF26-4ABC-AAE5-BEC8ADBEC7F4"
            },
            {
              "criteria": "cpe:2.3:a:daniel_stenberg:c-ares:1.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A69A0F2-412C-429C-9D75-6EE445DBEA93"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}