PT-2018-5766 · Dnsmasq+3 · Dnsmasq+3
Simon Kelley
·
Published
2018-01-19
·
Updated
2024-06-15
·
CVE-2017-15107
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Dnsmasq versions up to and including 2.78
Description:
A vulnerability was found in the implementation of DNSSEC in Dnsmasq. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
Recommendations:
For versions up to and including 2.78, update to a version that includes a fix for this issue to prevent improper interpretation of wildcard synthesized NSEC records.
Fix
Improperly Implemented Security Check for Standard
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Dnsmasq
Suse
Ubuntu