PowerDNS Remote Cache Poisoning Vulnerability
BID:28517
Info
PowerDNS Remote Cache Poisoning Vulnerability
| Bugtraq ID: | 28517 |
| Class: | Design Error |
| CVE: |
CVE-2008-1637 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2008 12:00AM |
| Updated: | Apr 13 2015 09:16PM |
| Credit: | Amit Klein |
| Vulnerable: |
SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 Redhat Fedora 7 PowerDNS PowerDNS 3.1.4 PowerDNS PowerDNS 3.1.3 PowerDNS PowerDNS 3.1.2 PowerDNS PowerDNS 3.1.1 PowerDNS PowerDNS 3.0.1 PowerDNS PowerDNS 3.0 PowerDNS PowerDNS 3.1 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
PowerDNS PowerDNS 3.1.5 |
Discussion
PowerDNS Remote Cache Poisoning Vulnerability
PowerDNS is prone to a remote cache-poisoning vulnerability because of a weakness in the use of random number generators.
An attacker may leverage this issue to manipulate cache data, potentially facilitating man-in-the-middle, site-impersonation, or denial-of-service attacks.
Versions prior to PowerDNS 3.1.5 are vulnerable to this issue.
PowerDNS is prone to a remote cache-poisoning vulnerability because of a weakness in the use of random number generators.
An attacker may leverage this issue to manipulate cache data, potentially facilitating man-in-the-middle, site-impersonation, or denial-of-service attacks.
Versions prior to PowerDNS 3.1.5 are vulnerable to this issue.
Exploit / POC
PowerDNS Remote Cache Poisoning Vulnerability
Example exploit code is available in the PDF document by Amit Klein. Please see the references for more information.
Example exploit code is available in the PDF document by Amit Klein. Please see the references for more information.
Solution / Fix
PowerDNS Remote Cache Poisoning Vulnerability
Solution:
The vendor has released an advisory along with PowerDNS 3.1.5 to address this issue. Please see the references for more information.
PowerDNS PowerDNS 3.1
PowerDNS PowerDNS 3.0
PowerDNS PowerDNS 3.0.1
PowerDNS PowerDNS 3.1.1
PowerDNS PowerDNS 3.1.2
PowerDNS PowerDNS 3.1.3
PowerDNS PowerDNS 3.1.4
Solution:
The vendor has released an advisory along with PowerDNS 3.1.5 to address this issue. Please see the references for more information.
PowerDNS PowerDNS 3.1
-
PowerDNS pdns-recursor-3.1.5.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.5.tar.bz2
PowerDNS PowerDNS 3.0
-
PowerDNS pdns-recursor-3.1.5.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.5.tar.bz2
PowerDNS PowerDNS 3.0.1
-
PowerDNS pdns-recursor-3.1.5.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.5.tar.bz2
PowerDNS PowerDNS 3.1.1
-
PowerDNS pdns-recursor-3.1.5.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.5.tar.bz2
PowerDNS PowerDNS 3.1.2
-
PowerDNS pdns-recursor-3.1.5.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.5.tar.bz2
PowerDNS PowerDNS 3.1.3
-
PowerDNS pdns-recursor-3.1.5.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.5.tar.bz2
PowerDNS PowerDNS 3.1.4
-
Debian pdns-recursor_3.1.4-1+etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4-1+etch1_alpha.deb -
Debian pdns-recursor_3.1.4-1+etch1_amd64.deb
amd64 architecture (AMD x86_64 (AMD64))
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4-1+etch1_amd64.deb -
Debian pdns-recursor_3.1.4-1+etch1_i386.deb
amd64 architecture (AMD x86_64 (AMD64))
http://security.debian.org/pool/updates/main/p/pdns-recursor/http://se curity.debian.org/pool/updates/main/p/pdns-recursor/pdns-recursor_3.1. 4-1+etch1_i386.deb -
Debian pdns-recursor_3.1.4-1+etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4-1+etch1_ia64.deb -
Debian pdns-recursor_3.1.4-1+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4-1+etch1_powerpc.deb -
Debian pdns-recursor_3.1.4-1+etch1_s390.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/http://se curity.debian.org/pool/updates/main/p/pdns-recursor/pdns-recursor_3.1. 4-1+etch1_s390.deb -
PowerDNS pdns-recursor-3.1.5.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.5.tar.bz2
References
PowerDNS Remote Cache Poisoning Vulnerability
References:
References:
- PowerDNS Product Page (PowerDNS)
- PowerDNS Recursor DNS Cache Poisoning (Amit Klein)
- PowerDNS Release Notes (PowerDNS)
- Paper by Amit Klein (Trusteer): "PowerDNS Recursor DNS Cache Poisoning [pharming (Amit Klein
) - PowerDNS Security Advisory 2008-01: System random generator can be predicted, le (PowerDNS)