Back to search
CVE-2008-1637
Published: Apr 2, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
29764
third-party-advisory
x_refsource_SECUNIA
29737
third-party-advisory
x_refsource_SECUNIA
DSA-1544
vendor-advisory
x_refsource_DEBIAN
FEDORA-2008-3010
vendor-advisory
x_refsource_FEDORA
28517
vdb-entry
x_refsource_BID
http://doc.powerdns.com/changelog.html
x_refsource_CONFIRM
http://www.trusteer.com/docs/powerdnsrecursor.html
x_refsource_MISC
29584
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2008:012
vendor-advisory
x_refsource_SUSE
ADV-2008-1046
vdb-entry
x_refsource_VUPEN
29830
third-party-advisory
x_refsource_SECUNIA
http://doc.powerdns.com/powerdns-advisory-2008-01.html
x_refsource_CONFIRM
powerdns-dnscache-weak-security(41534)
vdb-entry
x_refsource_XF
GLSA-200804-22
vendor-advisory
x_refsource_GENTOO
FEDORA-2008-3036
vendor-advisory
x_refsource_FEDORA
20080331 Paper by Amit Klein (Trusteer): "PowerDNS Recursor DNS Cache Poisoning [pharming]"
mailing-list
x_refsource_BUGTRAQ
30581
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now