Lucene search

K
githubGitHub Advisory DatabaseGHSA-HFMW-7G3M-GJ6Q
HistorySep 18, 2024 - 3:30 p.m.

CoreDNS vulnerable to TuDoor Attacks

2024-09-1815:30:52
GitHub Advisory Database
github.com
1
coredns
vulnerability
denial of service
resolver
exploit

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

17.7%

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.

Affected configurations

Vulners
Node
corednscorednsRange<1.11.0
VendorProductVersionCPE
corednscoredns*cpe:2.3:a:coredns:coredns:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

17.7%

Related for GHSA-HFMW-7G3M-GJ6Q