
fwdillema/totd
Releases3
Frequency2 months 3 weeks
Last Release
Stars21
DNS proxy and translator for IPv6 and IPv4
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 9.8 CRITICAL | — | ||
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks. | |||
| 6.5 MEDIUM | 4.3 MEDIUM | ||
totd before 1.5.3 does not properly randomize mesg IDs. | |||