PublicDate: 2008-07-18 16:41:00 UTC Candidate: CVE-2008-3217 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3217 Description: PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_pdns-recursor: upstream_pdns-recursor: released (3.1.7) dapper_pdns-recursor: DNE feisty_pdns-recursor: needed (reached end-of-life) gutsy_pdns-recursor: needed (reached end-of-life) hardy_pdns-recursor: ignored (reached end-of-life) intrepid_pdns-recursor: not-affected jaunty_pdns-recursor: not-affected karmic_pdns-recursor: not-affected lucid_pdns-recursor: not-affected maverick_pdns-recursor: not-affected natty_pdns-recursor: not-affected oneiric_pdns-recursor: not-affected devel_pdns-recursor: not-affected