Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15107

Опубликовано: 19 янв. 2018
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

A vulnerability was found in Dnsmasq's implementation of DNSSEC. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

Отчет

Versions of Dnsmasq shipped with Red Hat Enterprise Linux are built without DNSSEC support, so they are not affected by this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dnsmasqNot affected
Red Hat Enterprise Linux 6dnsmasqNot affected
Red Hat Enterprise Linux 7dnsmasqNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)dnsmasqNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)dnsmasqNot affected
Red Hat OpenStack Platform 10 (Newton)dnsmasqNot affected
Red Hat OpenStack Platform 11 (Ocata)dnsmasqNot affected
Red Hat OpenStack Platform 12 (Pike)dnsmasqNot affected
Red Hat OpenStack Platform 8 (Liberty)dnsmasqNot affected
Red Hat OpenStack Platform 9 (Mitaka)dnsmasqNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1510570dnsmasq: Improper validation of wildcard synthesized NSEC records

EPSS

Процентиль: 6%
0.00025
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

CVSS3: 7.5
nvd
около 8 лет назад

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

CVSS3: 7.5
debian
около 8 лет назад

A vulnerability was found in the implementation of DNSSEC in Dnsmasq u ...

suse-cvrf
больше 6 лет назад

Security update for dnsmasq

suse-cvrf
больше 6 лет назад

Security update for dnsmasq

EPSS

Процентиль: 6%
0.00025
Низкий

5.4 Medium

CVSS3