Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-3905

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 86.7%
CVSS Severity
CVSS v2 Score 5.8
References
Products affected by CVE-2008-3905
  • Ruby-Lang » Ruby » Version: Any
    cpe:2.3:a:ruby-lang:ruby:*
  • Ruby-Lang » Ruby » Version: N/A
    cpe:2.3:a:ruby-lang:ruby:-
  • Ruby-Lang » Ruby » Version: 1.6
    cpe:2.3:a:ruby-lang:ruby:1.6
  • Ruby-Lang » Ruby » Version: 1.6.8
    cpe:2.3:a:ruby-lang:ruby:1.6.8
  • Ruby-Lang » Ruby » Version: 1.8
    cpe:2.3:a:ruby-lang:ruby:1.8
  • Ruby-Lang » Ruby » Version: 1.8.0
    cpe:2.3:a:ruby-lang:ruby:1.8.0
  • Ruby-Lang » Ruby » Version: 1.8.1
    cpe:2.3:a:ruby-lang:ruby:1.8.1
  • Ruby-Lang » Ruby » Version: 1.8.2
    cpe:2.3:a:ruby-lang:ruby:1.8.2
  • Ruby-Lang » Ruby » Version: 1.8.3
    cpe:2.3:a:ruby-lang:ruby:1.8.3
  • Ruby-Lang » Ruby » Version: 1.8.4
    cpe:2.3:a:ruby-lang:ruby:1.8.4
  • Ruby-Lang » Ruby » Version: 1.8.5
    cpe:2.3:a:ruby-lang:ruby:1.8.5
  • Ruby-Lang » Ruby » Version: 1.8.6
    cpe:2.3:a:ruby-lang:ruby:1.8.6
  • Ruby-Lang » Ruby » Version: 1.8.7
    cpe:2.3:a:ruby-lang:ruby:1.8.7


Contact Us

Shodan ® - All rights reserved