PT-2022-2474 · Uclibc-Ng+2 · Uclibc-Ng+2
Andrea Palanca
+1
·
Published
2022-05-02
·
Updated
2023-08-08
·
CVE-2022-30295
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
uClibc-ng versions through 1.0.40
uClibc versions through 0.9.33.2
Description
The issue is related to the use of predictable DNS transaction IDs, which may lead to DNS cache poisoning. This is due to a reset of a value to 0x2. The vulnerability can be exploited by a remote attacker to send specially crafted DNS packets, potentially damaging the DNS cache with incorrect records and redirecting users to arbitrary sites.
Recommendations
For uClibc-ng versions through 1.0.40, update to a version later than 1.0.40 to resolve the issue.
For uClibc versions through 0.9.33.2, update to a version later than 0.9.33.2 to resolve the issue.
As a temporary workaround, consider restricting DNS query functionality until a patch is available.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Uclibc
Uclibc-Ng