CVE-2007-3377 describes a vulnerability in Header.pm of the Net::DNS Perl module, affecting versions prior to 0.60, including products like qpsmtp and SpamAssassin. The flaw stems from predictable DNS sequence IDs and the potential for child processes to reuse starting IDs, enabling remote attackers to spoof DNS responses. With a CVSS score of 4.3 (medium severity), it requires moderate attack complexity and primarily impacts integrity, with no known active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.14CPE matchmatch criteria | cpe:2.3:a:nlnet_labs:net_dns:0.14:*:*:*:*:*:*:* | ||
0.20CPE matchmatch criteria | cpe:2.3:a:nlnet_labs:net_dns:0.20:*:*:*:*:*:*:* | ||
0.21CPE matchmatch criteria | cpe:2.3:a:nlnet_labs:net_dns:0.21:*:*:*:*:*:*:* | ||
0.22CPE matchmatch criteria | cpe:2.3:a:nlnet_labs:net_dns:0.22:*:*:*:*:*:*:* | ||
0.23CPE matchmatch criteria | cpe:2.3:a:nlnet_labs:net_dns:0.23:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.