Информационная безопасность
[RU] switch to
English Version



CVECVE-2008-1637
СтатусCandidate
ОписаниеPowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.
PhaseAssigned (02.04.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1637
ReferencesBID : 28517
 BUGTRAQ : 20080331 Paper by Amit Klein (Trusteer): "PowerDNS Recursor DNS Cache Poisoning [pharming]"
 CONFIRM : http://doc.powerdns.com/changelog.html
 CONFIRM : http://doc.powerdns.com/powerdns-advisory-2008-01....
 FRSIRT : ADV-2008-1046
 MISC : http://www.trusteer.com/docs/PowerDNS_recursor_DNS...
 MISC : http://www.trusteer.com/docs/powerdnsrecursor.html
 SECUNIA : 29584
 XF : powerdns-dnscache-weak-security(41534)
SecurityVulns:Подмена DNS-записей во многих клиентах и серверах DNS

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server