CVE-2022-33989
Summary
| CVE | CVE-2022-33989 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-15 13:15:00 UTC |
| Updated | 2022-08-18 16:53:00 UTC |
| Description | dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks. |
Risk And Classification
Problem Types: CWE-331
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dproxy-nexgen Project | Dproxy-nexgen | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| dproxy - caching DNS proxy download | SourceForge.net | MISC | sourceforge.net | |
| XDRI Attacks - and - How to Enhance Resilience of Residential Routers | USENIX | MISC | www.usenix.org | |
| oss-security - Multiple DNS Cache poisoning vulnerabilities in dproxy and drpoxy-nexgen (CVE-2022-33988, CVE-2022-33989, CVE-2022-33990, CVE-2022-33991) | MISC | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.