CVE Database
/

CVE-2008-1637

Back to search

CVE-2008-1637

Published: Apr 2, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.

VendorProductVersions

n/a

n/a

affected
n/a

References

29764
third-party-advisory
x_refsource_SECUNIA
29737
third-party-advisory
x_refsource_SECUNIA
DSA-1544
vendor-advisory
x_refsource_DEBIAN
FEDORA-2008-3010
vendor-advisory
x_refsource_FEDORA
28517
vdb-entry
x_refsource_BID
29584
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2008:012
vendor-advisory
x_refsource_SUSE
ADV-2008-1046
vdb-entry
x_refsource_VUPEN
29830
third-party-advisory
x_refsource_SECUNIA
GLSA-200804-22
vendor-advisory
x_refsource_GENTOO
FEDORA-2008-3036
vendor-advisory
x_refsource_FEDORA
30581
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now