Input validation error in PowerDNS Authoritative - CVE-2008-3337

 

Input validation error in PowerDNS Authoritative - CVE-2008-3337

Published: June 21, 2025


Vulnerability identifier: #VU111734
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2008-3337
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DNS cache poisoning.

PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers


Affected software

PowerDNS Authoritative
Gentoo Linux
net-dns/pdns

How to mitigate CVE-2008-3337

Install updates from vendor's website.

PowerDNS Authoritative - update to 2.9.21.1
net-dns/pdns - update to 2.9.21.2

External References

Related Security Bulletins