VDB
CVE-2008-3217
CVE-2008-3217
PUBLISHED
CVSS 6.800000190734863 MEDIUM
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.
EPSS 0.00% · 0.2th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
0.00%
0.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| powerdns | recursor | 3.1.4, 0, 3.0 |
| n/a | n/a | * |
Timeline
- Jul 18, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://www.securityfocus.com/bid/30782 url
- [oss-security] 20080716 Re: CVE request: PowerDNS recursor source port randomization mailing-list
- http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179 url
- 31311 third-party-advisory
- [oss-security] 20080709 CVE request: PowerDNS recursor source port randomization mailing-list
- [oss-security] 20080710 Re: DNS vulnerability: other relevant software mailing-list
- http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6 url
- powerdns-recursor-rng-weak-security(43925) vdb
- FEDORA-2008-6893 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-3217 advisory