Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22176
HistoryDec 16, 2019 - 6:41 a.m.

Insecure Random Generator

2019-12-1606:41:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.002 Low

EPSS

Percentile

56.7%

github.com/miekg/dns uses an insecure random generation for transaction IDs. The default Id function uses an insecure math/rand function, resulting in predictable output and allowing an attacker to exploit the vulnerability to forge responses without being on path.

0.002 Low

EPSS

Percentile

56.7%