MEDIUM · 6.4

CVE-2008-3337

PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issu...

Vulnerability Description

PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
PowerdnsAuthoritative Server<= 2.9.21
PowerdnsPowerdnsAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-3337?

CVE-2008-3337 is a vulnerability with a CVSS score of 6.4 (MEDIUM). PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issu...

How severe is CVE-2008-3337?

CVE-2008-3337 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-3337?

Check the references section above for vendor advisories and patch information. Affected products include: Powerdns Authoritative Server, Powerdns Powerdns.