CVE-2022-33988 Information

Description

dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.

Reference

https://www.usenix.org/conference/usenixsecurity22/presentation/jeitner https://sourceforge.net/projects/dproxy/ https://www.openwall.com/lists/oss-security/2022/08/14/3

Share on: