Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3217

Опубликовано: 18 июл. 2008
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*
Версия до 3.1.5 (включая)
cpe:2.3:a:powerdns:recursor:3.0:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.4:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.0181
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
около 18 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

redhat
больше 18 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

debian
около 18 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest rando ...

github
больше 4 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

EPSS

Процентиль: 76%
0.0181
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189