Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-28452

Опубликовано: 18 сент. 2024
Источник: debian

Описание

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
corednsitppackage

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.

CVSS3: 5.9
github
больше 1 года назад

CoreDNS vulnerable to TuDoor Attacks

suse-cvrf
больше 1 года назад

Security update for coredns