PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.
Vector
NETWORK
Complexity
MEDIUM
Authentication
NONE
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL
Powerdns Recursor 3.1.5 (not an official CPE)
Powerdns Recursor 3.1.4 (not an official CPE)
Powerdns Recursor 3.1.2 (not an official CPE)
Powerdns Recursor 3.1.1 (not an official CPE)
Powerdns Recursor 3.0 (not an official CPE)
Powerdns Recursor 3.0.1 (not an official CPE)
Powerdns Recursor 3.1.3 (not an official CPE)