CVE-2008-1637
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.
PowerDNS Recursor anterior a 3.1.5 no emplea la suficiente aleatoriedad para calcular (1) los valores TRXID y (2) números de las fuentes de los puertos UDP; esto hace que sea más fácil a los atacantes remotos envenenar una caché de DNS relacionada con (a) deficiencias algorítmicas en las funciones rand y random de librerias externas, (b) uso de una semilla de 32-bit, y (3) elección del momento del día como la única semilla de información.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-02 CVE Reserved
- 2008-04-02 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-189: Numeric Errors
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://doc.powerdns.com/changelog.html | X_refsource_confirm | |
http://secunia.com/advisories/29737 | Third Party Advisory | |
http://secunia.com/advisories/29764 | Third Party Advisory | |
http://secunia.com/advisories/29830 | Third Party Advisory | |
http://secunia.com/advisories/30581 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/490330/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/28517 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1046/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41534 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://doc.powerdns.com/powerdns-advisory-2008-01.html | 2024-08-07 | |
http://secunia.com/advisories/29584 | 2024-08-07 | |
http://www.trusteer.com/docs/PowerDNS_recursor_DNS_Cache_Poisoning.pdf | 2024-08-07 | |
http://www.trusteer.com/docs/powerdnsrecursor.html | 2024-08-07 |
URL | Date | SRC |
---|