{"api_version":"1","generated_at":"2026-07-23T10:19:30+00:00","cve":"CVE-2008-3217","urls":{"html":"https://cve.report/CVE-2008-3217","api":"https://cve.report/api/cve/CVE-2008-3217.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3217","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3217"},"summary":{"title":"CVE-2008-3217","description":"PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning.  NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-07-18 16:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/30782","name":"http://www.securityfocus.com/bid/30782","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PowerDNS Source Port Randomization Remote Cache Poisoning Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2008/07/16/12","name":"http://www.openwall.com/lists/oss-security/2008/07/16/12","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE request: PowerDNS recursor source port randomization","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31311","name":"http://secunia.com/advisories/31311","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for pdns-recursor  - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6","name":"http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Release notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43925","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43925","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2008/07/09/10","name":"http://www.openwall.com/lists/oss-security/2008/07/09/10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE request: PowerDNS recursor source port randomization","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 9 Update: pdns-recursor-3.1.7-2.fc9","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179","name":"http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Changeset 1179 - PowerDNS - Trac","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2008/07/10/6","name":"http://www.openwall.com/lists/oss-security/2008/07/10/6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: DNS vulnerability: other relevant software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3217","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3217","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3217","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3217","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"3.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3217","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"3.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3217","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"3.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3217","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"3.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3217","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"3.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3217","vulnerable":"1","versionEndIncluding":"3.1.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:28:41.717Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[oss-security] 20080716 Re: CVE request: PowerDNS recursor source port randomization","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2008/07/16/12"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179"},{"name":"31311","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31311"},{"name":"[oss-security] 20080709 CVE request: PowerDNS recursor source port randomization","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2008/07/09/10"},{"name":"[oss-security] 20080710 Re: DNS vulnerability: other relevant software","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2008/07/10/6"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6"},{"name":"powerdns-recursor-rng-weak-security(43925)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43925"},{"name":"FEDORA-2008-6893","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html"},{"name":"30782","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30782"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning.  NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"[oss-security] 20080716 Re: CVE request: PowerDNS recursor source port randomization","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2008/07/16/12"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179"},{"name":"31311","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31311"},{"name":"[oss-security] 20080709 CVE request: PowerDNS recursor source port randomization","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2008/07/09/10"},{"name":"[oss-security] 20080710 Re: DNS vulnerability: other relevant software","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2008/07/10/6"},{"tags":["x_refsource_CONFIRM"],"url":"http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6"},{"name":"powerdns-recursor-rng-weak-security(43925)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43925"},{"name":"FEDORA-2008-6893","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html"},{"name":"30782","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30782"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3217","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning.  NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[oss-security] 20080716 Re: CVE request: PowerDNS recursor source port randomization","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2008/07/16/12"},{"name":"http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179","refsource":"CONFIRM","url":"http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179"},{"name":"31311","refsource":"SECUNIA","url":"http://secunia.com/advisories/31311"},{"name":"[oss-security] 20080709 CVE request: PowerDNS recursor source port randomization","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2008/07/09/10"},{"name":"[oss-security] 20080710 Re: DNS vulnerability: other relevant software","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2008/07/10/6"},{"name":"http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6","refsource":"CONFIRM","url":"http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6"},{"name":"powerdns-recursor-rng-weak-security(43925)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43925"},{"name":"FEDORA-2008-6893","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html"},{"name":"30782","refsource":"BID","url":"http://www.securityfocus.com/bid/30782"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3217","datePublished":"2008-07-18T16:00:00.000Z","dateReserved":"2008-07-18T00:00:00.000Z","dateUpdated":"2024-08-07T09:28:41.717Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-07-18 16:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*","versionEndIncluding":"3.1.5","matchCriteriaId":"AA8CA6BA-8533-47D2-99AE-F8AFDEF78A33"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:recursor:3.0:*:*:*:*:*:*:*","matchCriteriaId":"38DDFF27-8CBB-468D-9837-C74538E5EF0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:recursor:3.0.1:*:*:*:*:*:*:*","matchCriteriaId":"B3920499-3580-4EA6-AD56-6515C3B8495A"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:recursor:3.1.1:*:*:*:*:*:*:*","matchCriteriaId":"FA1E4934-6690-4A09-8E6E-FE7ED57B9DEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:recursor:3.1.2:*:*:*:*:*:*:*","matchCriteriaId":"D474CF9D-1898-46D3-80B1-2D3743265F56"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:recursor:3.1.3:*:*:*:*:*:*:*","matchCriteriaId":"E18F9C22-04BB-4081-89E0-E6989970EBCD"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:recursor:3.1.4:*:*:*:*:*:*:*","matchCriteriaId":"FD3E469E-EAE5-4BF1-BB69-6445FBBF96FF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3217","Ordinal":"1","Title":"CVE-2008-3217","CVE":"CVE-2008-3217","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3217","Ordinal":"1","NoteData":"PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning.  NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.","Type":"Description","Title":"CVE-2008-3217"},{"CveYear":"2008","CveId":"3217","Ordinal":"2","NoteData":"2008-07-18","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3217","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}