Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-6524

Опубликовано: 11 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-6524: dnsmasq security and bug fix update (MODERATE)

[2.85-14]

  • Backport Coverity fix to hide detected issue (#2156789)

[2.85-13]

  • Rebuild with modified gating settings

[2.85-12]

  • Make create logfile writeable by root (#2156789)

[2.85-11]

  • Do not create and search --local and --address=/x/# domains (#2209031)

[2.85-10]

  • Fix also dynamically set resolvers over dbus (#2186481)

[2.85-9]

  • Properly initialize domain parameter in dnssec mode (#2182342)

[2.85-8]

  • Correct possible crashes when server=/example.net/# is used (#2188712)

[2.85-7]

  • Limit offered EDNS0 size 1232 (CVE-2023-28450)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

dnsmasq

2.85-14.el9

dnsmasq-utils

2.85-14.el9

Oracle Linux x86_64

dnsmasq

2.85-14.el9

dnsmasq-utils

2.85-14.el9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

CVSS3: 7.5
redhat
больше 2 лет назад

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

An issue was discovered in Dnsmasq before 2.90. The default maximum ED ...