Lucene search

K
osvGoogleOSV:GHSA-44R7-7P62-Q3FR
HistoryMay 18, 2021 - 9:09 p.m.

miekg/dns insecurely generates random numbers

2021-05-1821:09:13
Google
osv.dev
11

0.002 Low

EPSS

Percentile

56.7%

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

CPENameOperatorVersion
github.com/miekg/dnslt1.1.25

0.002 Low

EPSS

Percentile

56.7%