[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2021:0150-01 -- Redhat dnsmasq

ID: oval:org.secpod.oval:def:69584Date: (C)2021-03-03   (M)2023-12-20
Class: PATCHFamily: unix




The dnsmasq packages contain Dnsmasq, a lightweight DNS forwarder and DHCP server. Security Fix: * dnsmasq: heap-based buffer overflow in sort_rrset when DNSSEC is enabled * dnsmasq: buffer overflow in extract_name due to missing length check when DNSSEC is enabled * dnsmasq: heap-based buffer overflow with large memcpy in get_rdata when DNSSEC is enabled * dnsmasq: loose address/port check in reply_query makes forging replies easier for an off-path attacker * dnsmasq: loose query name check in reply_query makes forging replies easier for an off-path attacker * dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker * dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset when DNSSEC is enabled For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Platform:
CentOS 8
Product:
dnsmasq
Reference:
RHSA-2021:0150-01
CVE-2020-25681
CVE-2020-25682
CVE-2020-25683
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2020-25687
CVE    7
CVE-2020-25686
CVE-2020-25685
CVE-2020-25684
CVE-2020-25683
...
CPE    2
cpe:/o:centos:centos:8
cpe:/a:thekelleys:dnsmasq

© SecPod Technologies