Описание
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
A flaw was found in the Dnsmasq application where a remote attacker can trigger a memory leak by sending specially crafted DHCP responses to the server. A successful attack is dependent on a specific configuration regarding the domain name set into the dnsmasq.conf file. Over time, the memory leak may cause the process to run out of memory and terminate, causing a denial of service.
Отчет
In Red Hat OpenStack Platform, which currently supports Red Hat Enterprise Linux 7.7, the dnsmasq package is pulled directly from the rhel-7-server-rpms channel. Red Hat OpenStack Platform's version is therefore unused, please ensure that the underlying Red Hat Enterprise Linux dnsmasq package is current.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | dnsmasq | Out of support scope | ||
| Red Hat Enterprise Linux 6 | dnsmasq | Out of support scope | ||
| Red Hat OpenStack Platform 10 (Newton) | dnsmasq | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | dnsmasq | Will not fix | ||
| Red Hat OpenStack Platform 14 (Rocky) | dnsmasq | Will not fix | ||
| Red Hat Enterprise Linux 7 | dnsmasq | Fixed | RHSA-2020:3878 | 29.09.2020 |
| Red Hat Enterprise Linux 8 | dnsmasq | Fixed | RHSA-2020:1715 | 28.04.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
A vulnerability was found in dnsmasq before version 2.81 where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
A vulnerability was found in dnsmasq before version 2.81, where the me ...
EPSS
3.7 Low
CVSS3