~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2014-4883

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2014-4883
2
 
PublicDate: 2014-11-27
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4883
5
 
 https://bugzilla.redhat.com/show_bug.cgi?id=1169008
6
 
 http://www.kb.cert.org/vuls/id/210620
7
 
 http://git.savannah.gnu.org/cgit/lwip.git/commit/?id=9fb46e120655ac481b2af8f865d5ae56c39b831a
8
 
Description:
9
 
 resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP
10
 
 1.4.1 and earlier, does not use random values for ID fields and source
11
 
 ports of DNS query packets, which makes it easier for man-in-the-middle
12
 
 attackers to conduct cache-poisoning attacks via spoofed reply packets.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_lwipv6:
21
 
upstream_lwipv6: needs-triage
22
 
lucid_lwipv6: ignored (reached end-of-life)
23
 
precise_lwipv6: ignored (reached end-of-life)
24
 
precise/esm_lwipv6: DNE (precise was needed)
25
 
trusty_lwipv6: needed
26
 
utopic_lwipv6: ignored (reached end-of-life)
27
 
vivid_lwipv6: ignored (reached end-of-life)
28
 
vivid/stable-phone-overlay_lwipv6: DNE
29
 
vivid/ubuntu-core_lwipv6: DNE
30
 
wily_lwipv6: ignored (reached end-of-life)
31
 
xenial_lwipv6: needed
32
 
yakkety_lwipv6: ignored (reached end-of-life)
33
 
zesty_lwipv6: ignored (reached end-of-life)
34
 
artful_lwipv6: needed
35
 
bionic_lwipv6: needed
36
 
devel_lwipv6: needed