Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44r7-7p62-q3fr

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

miekg/dns insecurely generates random numbers

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

Пакеты

Наименование

github.com/miekg/dns

go
Затронутые версииВерсия исправления

< 1.1.25

1.1.25

EPSS

Процентиль: 53%
0.00297
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-330
CWE-338

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 6 лет назад

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

CVSS3: 5.9
redhat
около 6 лет назад

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

CVSS3: 5.9
nvd
около 6 лет назад

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

CVSS3: 5.9
debian
около 6 лет назад

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6. ...

EPSS

Процентиль: 53%
0.00297
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-330
CWE-338