CVE-2008-3217
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.
PowerDNS Recursor anterior a 3.1.6 no utiliza siempre el generador de números aleatorios más robusto para la selección de un puerto de origen, lo que le hace más fácil para los vectores de ataque remotos para llevar a cabo un ataque por envenenamiento de caché DNS. NOTA: Esto está relacionado con la incompleta integración de las mejoras de la seguridad asociados con CVE-2008-1637.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-07-18 CVE Reserved
- 2008-07-18 CVE Published
- 2024-07-24 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6 | X_refsource_confirm | |
http://secunia.com/advisories/31311 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2008/07/09/10 | Mailing List | |
http://www.openwall.com/lists/oss-security/2008/07/10/6 | Mailing List | |
http://www.openwall.com/lists/oss-security/2008/07/16/12 | Mailing List | |
http://www.securityfocus.com/bid/30782 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43925 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179 | 2017-08-08 |
URL | Date | SRC |
---|---|---|
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Powerdns Search vendor "Powerdns" | Recursor Search vendor "Powerdns" for product "Recursor" | <= 3.1.5 Search vendor "Powerdns" for product "Recursor" and version " <= 3.1.5" | - |
Affected
| ||||||
Powerdns Search vendor "Powerdns" | Recursor Search vendor "Powerdns" for product "Recursor" | 3.0 Search vendor "Powerdns" for product "Recursor" and version "3.0" | - |
Affected
| ||||||
Powerdns Search vendor "Powerdns" | Recursor Search vendor "Powerdns" for product "Recursor" | 3.0.1 Search vendor "Powerdns" for product "Recursor" and version "3.0.1" | - |
Affected
| ||||||
Powerdns Search vendor "Powerdns" | Recursor Search vendor "Powerdns" for product "Recursor" | 3.1.1 Search vendor "Powerdns" for product "Recursor" and version "3.1.1" | - |
Affected
| ||||||
Powerdns Search vendor "Powerdns" | Recursor Search vendor "Powerdns" for product "Recursor" | 3.1.2 Search vendor "Powerdns" for product "Recursor" and version "3.1.2" | - |
Affected
| ||||||
Powerdns Search vendor "Powerdns" | Recursor Search vendor "Powerdns" for product "Recursor" | 3.1.3 Search vendor "Powerdns" for product "Recursor" and version "3.1.3" | - |
Affected
| ||||||
Powerdns Search vendor "Powerdns" | Recursor Search vendor "Powerdns" for product "Recursor" | 3.1.4 Search vendor "Powerdns" for product "Recursor" and version "3.1.4" | - |
Affected
|