github.com/miekg/dns
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/miekg/dnspage 1 of 1
- CVE-2017-15133HIGHCVSS 7.5EG 7.5fixed in 1.0.4 or 1.0.4-0.20180125103619-43913f2f4fbd, by version range2018-01-29
A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from accepting new connections.
- CVE-2018-17419HIGHCVSS 7.5EG 7.5fixed in 1.0.102019-03-07
An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.
- CVE-2019-19794MEDIUMCVSS 5.9EG 5.9fixed in 1.1.25 or 1.1.25-0.20191211073109-8ebf2e419df7, by version range2019-12-13
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
Check whether github.com/miekg/dns is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/miekg/dns CVEs against the assets you own.
Book a Demo →