CVE-2008-3217
Summary
| CVE | CVE-2008-3217 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-07-18 16:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Powerdns | Recursor | 3.0 | All | All | All |
| Application | Powerdns | Recursor | 3.0.1 | All | All | All |
| Application | Powerdns | Recursor | 3.1.1 | All | All | All |
| Application | Powerdns | Recursor | 3.1.2 | All | All | All |
| Application | Powerdns | Recursor | 3.1.3 | All | All | All |
| Application | Powerdns | Recursor | 3.1.4 | All | All | All |
| Application | Powerdns | Recursor | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PowerDNS Source Port Randomization Remote Cache Poisoning Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - Re: CVE request: PowerDNS recursor source port randomization | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Fedora update for pdns-recursor - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Release notes | af854a3a-2127-422b-91ae-364da2661108 | doc.powerdns.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| oss-security - CVE request: PowerDNS recursor source port randomization | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [SECURITY] Fedora 9 Update: pdns-recursor-3.1.7-2.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Changeset 1179 - PowerDNS - Trac | af854a3a-2127-422b-91ae-364da2661108 | wiki.powerdns.com | Patch |
| oss-security - Re: DNS vulnerability: other relevant software | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.