Required CVE Record Information
Description
eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.
References 3 Total
- osvdb.org: 35584 vdb-entry
- securityfocus.com: 23577 vdb-entry
- archives.neohapsis.com: 20070420 eXtremail-v9 mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- osvdb.org: 35584 vdb-entryx_transferred
- securityfocus.com: 23577 vdb-entryx_transferred
- archives.neohapsis.com: 20070420 eXtremail-v9 mailing-listx_transferred