MEDIUM
GHSA-gv9j-4w24-q7vx
Improper random number generation in github.com/coredns/coredns
Quick fix
GHSA-gv9j-4w24-q7vx — github.com/coredns/coredns: upgrade to the fixed version with the command below.
go get github.com/coredns/coredns@v1.6.6Details
### Impact
CoreDNS before 1.6.6 (using go DNS package < 1.1.25) improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
### Patches The problem has been fixed in 1.6.6+.
### References - [CVE-2019-19794](https://nvd.nist.gov/vuln/detail/CVE-2019-19794)
### For more information Please consult [our security guide](https://github.com/coredns/coredns/blob/master/.github/SECURITY.md) for more information regarding our security process.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/coredns/coredns
Introduced in:
0Fixed in: 1.6.6Fix
go get github.com/coredns/coredns@v1.6.6