CVE-2008-4392
Status: ModifiedMedium (6.4)—
dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P
- Base score: 6.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.69%
- Percentile among all scored CVEs: 76
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-362
References
- http://secunia.com/advisories/33855
- http://www.securityfocus.com/bid/33818
- http://www.your.org/dnscache/
- http://www.your.org/dnscache/djbdns.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48807
- http://secunia.com/advisories/33855
- http://www.securityfocus.com/bid/33818
- http://www.your.org/dnscache/
- http://www.your.org/dnscache/djbdns.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48807
Raw JSON (NVD)
Show
{
"id": "CVE-2008-4392",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-02-19T16:30:00.327",
"references": [
{
"url": "http://secunia.com/advisories/33855",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/33818",
"source": "cret@cert.org"
},
{
"url": "http://www.your.org/dnscache/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.your.org/dnscache/djbdns.pdf",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48807",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/33855",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/33818",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.your.org/dnscache/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.your.org/dnscache/djbdns.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48807",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query."
},
{
"lang": "es",
"value": "dnscache en Daniel J. Bernstein djbdns v1.05 no previene peticiones DNS de salida idénticas simultáneas, lo cual hace más sencillo a atacantes remotos envenenar respuestas DNS, como lo demostrado por un registro A envenenado en la sección \"Additional\" de una respuesta a un petición \"Start of Authority\" (SOA)."
}
],
"lastModified": "2026-06-16T22:57:43.650",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:d.j.bernstein:djbdns:1.05:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC196644-7220-46EF-92CF-87F9BD45AEF5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}