CVE Vulnerabilities

CVE-2008-3217

Published: Jul 18, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

Affected Software

NameVendorStart VersionEnd Version
RecursorPowerdns*3.1.5 (including)
RecursorPowerdns3.0 (including)3.0 (including)
RecursorPowerdns3.0.1 (including)3.0.1 (including)
RecursorPowerdns3.1.1 (including)3.1.1 (including)
RecursorPowerdns3.1.2 (including)3.1.2 (including)
RecursorPowerdns3.1.3 (including)3.1.3 (including)
RecursorPowerdns3.1.4 (including)3.1.4 (including)
Pdns-recursorUbuntufeisty*
Pdns-recursorUbuntugutsy*
Pdns-recursorUbuntuhardy*
Pdns-recursorUbuntuupstream*

References