CVE-2008-1637

Publication date 2 April 2008

Last updated 24 July 2024


Ubuntu priority

PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.

Status

Package Ubuntu Release Status
pdns-recursor 8.10 intrepid
Fixed 3.1.4-6ubuntu1
8.04 LTS hardy
Fixed 3.1.4-6ubuntu1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Not in release