CVE Vulnerabilities

CVE-2008-3217

Published: Jul 18, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

Affected Software

Name Vendor Start Version End Version
Recursor Powerdns * 3.1.5 (including)
Recursor Powerdns 3.0 (including) 3.0 (including)
Recursor Powerdns 3.0.1 (including) 3.0.1 (including)
Recursor Powerdns 3.1.1 (including) 3.1.1 (including)
Recursor Powerdns 3.1.2 (including) 3.1.2 (including)
Recursor Powerdns 3.1.3 (including) 3.1.3 (including)
Recursor Powerdns 3.1.4 (including) 3.1.4 (including)
Pdns-recursor Ubuntu feisty *
Pdns-recursor Ubuntu gutsy *
Pdns-recursor Ubuntu hardy *
Pdns-recursor Ubuntu upstream *

References