VYPR
Unrated severityNVD Advisory· Published Sep 4, 2008· Updated Apr 23, 2026

CVE-2008-3905

CVE-2008-3905

Description

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

Affected products

27
  • Ruby Lang/Ruby27 versions
    cpe:2.3:a:ruby-lang:ruby:1.8.7:preview3:*:*:*:*:*:*+ 26 more
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:preview3:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:preview4:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*range: <=1.8.5
    • cpe:2.3:a:ruby-lang:ruby:*:p286:*:*:*:*:*:*range: <=1.8.6
    • cpe:2.3:a:ruby-lang:ruby:*:p71:*:*:*:*:*:*range: <=1.8.7
    • cpe:2.3:a:ruby-lang:ruby:*:r18423:*:*:*:*:*:*range: <=1.9
    • cpe:2.3:a:ruby-lang:ruby:1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:p110:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:p111:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:p114:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:p230:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:p36:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:preview1:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:preview2:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.6:preview3:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:p17:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:p22:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:preview1:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.8.7:preview2:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

24

News mentions

0

No linked articles in our index yet.