CVE-2007-3898

The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
References
Link Resource
http://secunia.com/advisories/27584 Patch Vendor Advisory
http://securityreason.com/securityalert/3373
http://www.kb.cert.org/vuls/id/484649 US Government Resource
http://www.scanit.be/advisory-2007-11-14.html
http://www.securityfocus.com/archive/1/483635/100/0/threaded
http://www.securityfocus.com/archive/1/483698/100/0/threaded
http://www.securityfocus.com/archive/1/484186/100/0/threaded
http://www.securityfocus.com/archive/1/484186/100/0/threaded
http://www.securityfocus.com/bid/25919 Exploit Patch
http://www.securitytracker.com/id?1018942
http://www.trusteer.com/docs/windowsdns.html
http://www.us-cert.gov/cas/techalerts/TA07-317A.html US Government Resource
http://www.vupen.com/english/advisories/2007/3848
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-062
https://exchange.xforce.ibmcloud.com/vulnerabilities/36805
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4395
http://secunia.com/advisories/27584 Patch Vendor Advisory
http://securityreason.com/securityalert/3373
http://www.kb.cert.org/vuls/id/484649 US Government Resource
http://www.scanit.be/advisory-2007-11-14.html
http://www.securityfocus.com/archive/1/483635/100/0/threaded
http://www.securityfocus.com/archive/1/483698/100/0/threaded
http://www.securityfocus.com/archive/1/484186/100/0/threaded
http://www.securityfocus.com/archive/1/484186/100/0/threaded
http://www.securityfocus.com/bid/25919 Exploit Patch
http://www.securitytracker.com/id?1018942
http://www.trusteer.com/docs/windowsdns.html
http://www.us-cert.gov/cas/techalerts/TA07-317A.html US Government Resource
http://www.vupen.com/english/advisories/2007/3848
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-062
https://exchange.xforce.ibmcloud.com/vulnerabilities/36805
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4395
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_2000:*:gold:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:gold:adv_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:gold:datacenter_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:gold:srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:adv_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:datacenter_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:adv_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:datacenter_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:adv_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:datacenter_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:adv_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:datacenter_srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:srv:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:gold:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:gold:itanium:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:gold:std:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:gold:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:gold:x64-std:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp1:std:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:std:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:-:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*

History

21 Nov 2024, 00:34

Type Values Removed Values Added
References () http://secunia.com/advisories/27584 - Patch, Vendor Advisory () http://secunia.com/advisories/27584 - Patch, Vendor Advisory
References () http://securityreason.com/securityalert/3373 - () http://securityreason.com/securityalert/3373 -
References () http://www.kb.cert.org/vuls/id/484649 - US Government Resource () http://www.kb.cert.org/vuls/id/484649 - US Government Resource
References () http://www.scanit.be/advisory-2007-11-14.html - () http://www.scanit.be/advisory-2007-11-14.html -
References () http://www.securityfocus.com/archive/1/483635/100/0/threaded - () http://www.securityfocus.com/archive/1/483635/100/0/threaded -
References () http://www.securityfocus.com/archive/1/483698/100/0/threaded - () http://www.securityfocus.com/archive/1/483698/100/0/threaded -
References () http://www.securityfocus.com/archive/1/484186/100/0/threaded - () http://www.securityfocus.com/archive/1/484186/100/0/threaded -
References () http://www.securityfocus.com/bid/25919 - Exploit, Patch () http://www.securityfocus.com/bid/25919 - Exploit, Patch
References () http://www.securitytracker.com/id?1018942 - () http://www.securitytracker.com/id?1018942 -
References () http://www.trusteer.com/docs/windowsdns.html - () http://www.trusteer.com/docs/windowsdns.html -
References () http://www.us-cert.gov/cas/techalerts/TA07-317A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-317A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2007/3848 - () http://www.vupen.com/english/advisories/2007/3848 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-062 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-062 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/36805 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/36805 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4395 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4395 -

Information

Published : 2007-11-14 01:46

Updated : 2024-11-21 00:34


NVD link : CVE-2007-3898

Mitre link : CVE-2007-3898

CVE.ORG link : CVE-2007-3898


JSON object : View

Products Affected

microsoft

  • windows_server_2003
  • windows_2003_server
  • windows_2000
CWE
CWE-16

Configuration