Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
非Windows平台上的c-ares DNS欺骗漏洞
Vulnerability Description
非Windows平台上的c-ares中存在DNS欺骗漏洞。ares_init:randomize_key函数为创建一个随机数字序列(Unix rand)使用弱工具,这使得远程攻击者更易于通过猜测出特定值,来哄骗DNS响应。
CVSS Information
N/A
Vulnerability Type
N/A