CVE-2007-3153

Publication date

2007-06-11 22:00:00

Family

mitre

State

PUBLISHED

Description

The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.