Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-4883
Description:resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in- the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.
Test IDs: 1.3.6.1.4.1.25623.1.0.108826  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-4883
CERT/CC vulnerability note: VU#210620
http://www.kb.cert.org/vuls/id/210620




© 1998-2025 E-Soft Inc. All rights reserved.