totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-08-15T11:53:52

Updated: 2022-08-15T11:53:52

Reserved: 2022-06-22T00:00:00


Link: CVE-2022-34294

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-15T12:15:19.963

Modified: 2023-08-08T14:22:24.967


Link: CVE-2022-34294

JSON object: View

cve-icon Redhat Information

No data.

CWE