CVE-2008-3217
Estado: ModificadaMedia (6.8)—
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.81%
- Percentil entre todas las CVEs puntuadas: 78
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-189
Referencias
- http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6
- http://secunia.com/advisories/31311
- http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179
- http://www.openwall.com/lists/oss-security/2008/07/09/10
- http://www.openwall.com/lists/oss-security/2008/07/10/6
- http://www.openwall.com/lists/oss-security/2008/07/16/12
- http://www.securityfocus.com/bid/30782
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43925
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html
- http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6
- http://secunia.com/advisories/31311
- http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179
- http://www.openwall.com/lists/oss-security/2008/07/09/10
- http://www.openwall.com/lists/oss-security/2008/07/10/6
- http://www.openwall.com/lists/oss-security/2008/07/16/12
- http://www.securityfocus.com/bid/30782
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43925
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-3217",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-07-18T16:41:00.000",
"references": [
{
"url": "http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31311",
"source": "cve@mitre.org"
},
{
"url": "http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/07/09/10",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/07/10/6",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/07/16/12",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/30782",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43925",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html",
"source": "cve@mitre.org"
},
{
"url": "http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-6",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31311",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wiki.powerdns.com/cgi-bin/trac.fcgi/changeset/1179",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/07/09/10",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/07/10/6",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/07/16/12",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/30782",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43925",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01353.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-189"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637."
},
{
"lang": "es",
"value": "PowerDNS Recursor anterior a 3.1.6 no utiliza siempre el generador de números aleatorios más robusto para la selección de un puerto de origen, lo que le hace más fácil para los vectores de ataque remotos para llevar a cabo un ataque por envenenamiento de caché DNS. NOTA: Esto está relacionado con la incompleta integración de las mejoras de la seguridad asociados con CVE-2008-1637."
}
],
"lastModified": "2026-06-16T22:55:23.753",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA8CA6BA-8533-47D2-99AE-F8AFDEF78A33",
"versionEndIncluding": "3.1.5"
},
{
"criteria": "cpe:2.3:a:powerdns:recursor:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38DDFF27-8CBB-468D-9837-C74538E5EF0A"
},
{
"criteria": "cpe:2.3:a:powerdns:recursor:3.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3920499-3580-4EA6-AD56-6515C3B8495A"
},
{
"criteria": "cpe:2.3:a:powerdns:recursor:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA1E4934-6690-4A09-8E6E-FE7ED57B9DEE"
},
{
"criteria": "cpe:2.3:a:powerdns:recursor:3.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D474CF9D-1898-46D3-80B1-2D3743265F56"
},
{
"criteria": "cpe:2.3:a:powerdns:recursor:3.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E18F9C22-04BB-4081-89E0-E6989970EBCD"
},
{
"criteria": "cpe:2.3:a:powerdns:recursor:3.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD3E469E-EAE5-4BF1-BB69-6445FBBF96FF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}