Описание
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
A vulnerability was found in Dnsmasq's implementation of DNSSEC. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
Отчет
Versions of Dnsmasq shipped with Red Hat Enterprise Linux are built without DNSSEC support, so they are not affected by this issue.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux 6 | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux 7 | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 11 (Ocata) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 12 (Pike) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 9 (Mitaka) | dnsmasq | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
A vulnerability was found in the implementation of DNSSEC in Dnsmasq u ...
EPSS
5.4 Medium
CVSS3