PowerDNS Information for VU#800113
Multiple DNS implementations vulnerable to cache poisoning
- Vendor Information Help Date Notified: 13 May 2008
- Statement Date: 06 Jun 2008
- Date Updated: 10 Jul 2008
PowerDNS Vendor Statement
Since version 3.0, released in April 2006, the PowerDNS Recursor resolving
nameserver has implemented measures that protect against the vulnerability
described in CVE-2008-1447. Source ports are randomized, and 'near misses',
indicating a spoofing attempt in progress, are detected, and the query is
Although all 3.x versions implement these measures, from 3.1.6 a
cryptographically secure random generator is used which further enhances
protection against spoofing, so an upgrade to 3.1.6 or higher is advised.
We are not aware of further vendor information regarding this vulnerability.
There are no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.