Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15107

Опубликовано: 23 янв. 2018
Источник: debian

Описание

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.79-1package
dnsmasqno-dsastretchpackage
dnsmasqno-dsajessiepackage
dnsmasqno-dsawheezypackage

Примечания

  • http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2018q1/011896.html

  • https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=4fe6744a220eddd3f1749b40cac3dfc510787de6

  • https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=cd7df612b14ec1bf831a966ccaf076be0dae7404

  • https://medium.com/nlnetlabs/the-peculiar-case-of-nsec-processing-using-expanded-wildcard-records-ae8285f236be

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

CVSS3: 5.4
redhat
около 8 лет назад

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

CVSS3: 7.5
nvd
около 8 лет назад

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

suse-cvrf
больше 6 лет назад

Security update for dnsmasq

suse-cvrf
больше 6 лет назад

Security update for dnsmasq