pdns-recursor: DNS cache poisoning
Package(s): | pdns-recursor | CVE #(s): | CVE-2008-1637 | ||||||||||||||||||||||||||||
Created: | April 9, 2008 | Updated: | August 21, 2008 | ||||||||||||||||||||||||||||
Description: | From the Red Hat bugzilla entry: Amit Klein of Trusteer discovered and documented weakness in a way PowerDNS Recursor generates DNS queries and transaction IDs used in DNS queries. This weakness can be used to predict transaction IDs used in a subsequent queries after observing certain amount of consequent previous queries, leading to a high possibility of performing a successful cache poisoning attack. | ||||||||||||||||||||||||||||||
Alerts: |
|