dproxy-nexgen (aka dproxy nexgen) re-uses the DNS...
High severity
Unreviewed
Published
Aug 16, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Aug 15, 2022
Published to the GitHub Advisory Database
Aug 16, 2022
Last updated
Jan 29, 2023
dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.
References