Releases88
Frequency1 month 3 days
Last Release
Stars8.73K
DNS library in Go

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 1.1.255.9 MEDIUM4.3 MEDIUM

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

7.5 HIGH5 MEDIUM

An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.

< 1.0.45 MEDIUM

A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from accepting new connections.