Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-1637
StatusCandidate
DescriptionPowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.
PhaseAssigned (02.04.2008)
SecurityVulns:Multiple DNS servers and clients DNS records spoofing
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1637
ReferencesBID : 28517
 BUGTRAQ : 20080331 Paper by Amit Klein (Trusteer): "PowerDNS Recursor DNS Cache Poisoning [pharming]"
 CONFIRM : http://doc.powerdns.com/changelog.html
 CONFIRM : http://doc.powerdns.com/powerdns-advisory-2008-01....
 FRSIRT : ADV-2008-1046
 MISC : http://www.trusteer.com/docs/PowerDNS_recursor_DNS...
 MISC : http://www.trusteer.com/docs/powerdnsrecursor.html
 SECUNIA : 29584
 XF : powerdns-dnscache-weak-security(41534)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru