The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."
CVSS Details
- CVSS 3.1 Base Score: 6.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Bind | — | Apply OS X security update 2008-005 | Dec 16, 2011 | Jul 8, 2008 |
| Apple Osx Libresolv | — | Upgrade macOS to the latest versionApply OS X security update 2008-006 | Dec 16, 2011 | Jul 8, 2008 |
| Apple Osx Mdnsresponder | — | Upgrade macOS to the latest versionApply OS X security update 2008-006 | Dec 16, 2011 | Jul 8, 2008 |
| Debian | — | Upgrade dnspythonUpgrade udnsUpgrade libnet-dns-perlUpgrade bind9Upgrade refpolicyUpgrade dnsmasqUpgrade adns | Jul 30, 2024 | Jul 8, 2008 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 19, 2013 |
| Freebsd | — | Upgrade FreeBSDUpgrade ruby+onigurumaUpgrade ruby+pthreadsUpgrade ruby+pthreads+onigurumaUpgrade ruby | Dec 10, 2025 | Aug 16, 2008 |
| Gentoo Linux | — | Upgrade app-emulation/vmware-server.Upgrade app-emulation/vmware-workstation.Upgrade net-dns/bind.Upgrade dev-lang/ruby.Upgrade app-emulation/vmware-player.Upgrade net-dns/pdnsd.Upgrade net-dns/dnsmasq. | Oct 30, 2017 | Jul 8, 2008 |
| Hpux | — | Update InternetSrvcs.INETSVCS-RUN to the latest versionUpdate BINDv920.INETSVCS-BIND to the latest versionUpdate BindUpgrade.BIND-UPGRADE to the latest versionUpdate NameService.BIND-RUN to the latest versionUpdate NameService.BIND-AUX to the latest versionUpdate BindUpgrade.BIND2-UPGRADE to the latest versionApply patch PHNE_37865 from HP | Aug 11, 2017 | Jul 8, 2008 |
| Oracle_linux | — | Upgrade bindUpgrade selinux-policy-mlsUpgrade bind-develUpgrade bind-libbind-develUpgrade selinux-policy-targetedUpgrade bind-utilsUpgrade bind-sdbUpgrade bind-libsUpgrade bind-chrootUpgrade caching-nameserverUpgrade selinux-policy-develUpgrade dnsmasqUpgrade selinux-policyUpgrade selinux-policy-strict | Oct 16, 2024 | Jul 8, 2008 |
| Suse | — | Upgrade bind-devel-64bitUpgrade bind-libs-64bitUpgrade bind-chrootenvUpgrade bind-utilsUpgrade bind-develUpgrade bind-utils-64bitUpgrade suse-releaseUpgrade bind-libs-32bitUpgrade bind-libsUpgrade bind-utils-32bitUpgrade bindUpgrade bind-utils-x86Upgrade dnsmasqUpgrade bind-doc | Feb 17, 2015 | Jul 8, 2008 |
| Ubuntu | — | Upgrade dnsmasq-baseUpgrade libdns22Upgrade libdns35Upgrade libdns32Upgrade libdns21 | Nov 8, 2024 | Jul 8, 2008 |
| Vmsa 2008 0014 | — | Apply ESX350-200808409-SG. | Nov 19, 2010 | Jul 8, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub