Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3217

Опубликовано: 18 июл. 2008
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*
Версия до 3.1.5 (включая)
cpe:2.3:a:powerdns:recursor:3.0:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.1.4:*:*:*:*:*:*:*

EPSS

Процентиль: 0%
0.00004
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
больше 17 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

redhat
больше 17 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

debian
больше 17 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest rando ...

github
больше 3 лет назад

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

EPSS

Процентиль: 0%
0.00004
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-189