Total vulnerabilities in the database
The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.
Software | From | Fixed in |
---|---|---|
daniel_stenberg / c-ares | 1.3 | 1.3.x |
daniel_stenberg / c-ares | 1.0 | 1.0.x |
daniel_stenberg / c-ares | 1.3.2 | 1.3.2.x |
daniel_stenberg / c-ares | 1.2.1 | 1.2.1.x |
daniel_stenberg / c-ares | 1.2 | 1.2.x |
daniel_stenberg / c-ares | 1.3.1 | 1.3.1.x |
daniel_stenberg / c-ares | 1.1 | 1.1.x |