Skip to content

[Security] CVE-2019-19794

Moderate
yongtang published GHSA-gv9j-4w24-q7vx Feb 26, 2022

Package

gomod coredns (Go)

Affected versions

< 1.6.6

Patched versions

1.6.6

Description

Impact

CoreDNS before 1.6.6 (using go DNS package < 1.1.25) improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

Patches

The problem has been fixed in 1.6.6+.

References

For more information

Please consult our security guide for more information regarding our security process.

Severity

Moderate

CVE ID

CVE-2019-19794

Weaknesses

No CWEs