CVE

Id
72180  
CVE No.
CVE-2014-4883  
Status
Candidate  
Description
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.  
Phase
Assigned (20140710)  
Votes
None (candidate not yet proposed)  
Comments