Skip to content

Improper random number generation in github.com/coredns/coredns

Moderate severity GitHub Reviewed Published Feb 26, 2022 in coredns/coredns • Updated Jan 11, 2023

Package

gomod github.com/coredns/coredns (Go)

Affected versions

< 1.6.6

Patched versions

1.6.6

Description

Impact

CoreDNS before 1.6.6 (using go DNS package < 1.1.25) improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

Patches

The problem has been fixed in 1.6.6+.

References

For more information

Please consult our security guide for more information regarding our security process.

References

@yongtang yongtang published to coredns/coredns Feb 26, 2022
Published to the GitHub Advisory Database Mar 1, 2022
Reviewed Mar 1, 2022
Last updated Jan 11, 2023

Severity

Moderate

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-gv9j-4w24-q7vx

Source code

github.com/coredns/coredns
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.