SB2008080805 - DNS cache poisoning in PowerDNS Authoritative



SB2008080805 - DNS cache poisoning in PowerDNS Authoritative

Published: August 8, 2008 Updated: June 21, 2025

Security Bulletin ID SB2008080805
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2008-3337)

The vulnerability allows a remote attacker to perform DNS cache poisoning.

PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers


Remediation

Install update from vendor's website.