CVE-2008-3337Improper Input Validation in Authoritative Server

Severity
6.4MEDIUMNVD
CNA6.8OSV6.8
EPSS
0.0%
top 94.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 1

Description

PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

Debianopen-xchange/pdns< 2.9.21.1-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rj9p-mrcp-3f7h: PowerDNS Authoritative Server before 22022-05-01
OSV
CVE-2008-3337: PowerDNS Authoritative Server before 22008-08-08
CVEList
CVE-2008-3337: PowerDNS Authoritative Server before 22008-08-08

📋Vendor Advisories

2
Debian
CVE-2008-3337: pdns - PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which mig...2008
Red Hat
pdns: not responding invalid queries my simplify spoofing attacks

💬Community

1
Bugzilla
CVE-2008-3337 pdns: not responding invalid queries my simplify spoofing attacks2008-08-06
CVE-2008-3337 — Improper Input Validation | cvebase