Описание
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | osp-director-provisioner-container | Affected | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8-tech-preview/osp-director-downloader | Will not fix | ||
| Red Hat OpenShift Jaeger 1.20 | distributed-tracing/jaeger-rhel8-operator | Fixed | RHSA-2020:5198 | 24.11.2020 |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8-tech-preview/osp-director-operator | Fixed | RHSA-2022:2183 | 11.05.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6. ...
EPSS
5.9 Medium
CVSS3