CVE-2022-30295
06.05.2022, 05:15
uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.Enginsight
Vendor | Product | Version |
---|---|---|
uclibc | uclibc | 𝑥 ≤ 0.9.33.2 |
uclibc-ng_project | uclibc-ng | 𝑥 ≤ 1.0.40 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
References