Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45955

Опубликовано: 01 янв. 2022
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge." However, a contributor states that a security patch (mentioned in 016162.html) is needed

A heap-based out-of-bounds WRITE flaw was found in dnsmasq. A remote attacker who can trigger a packet resize can use this flaw to write up to 50 bytes to the heap via a memmove call.

Отчет

Red Hat Product Security does not consider this to be a vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dnsmasqNot affected
Red Hat Enterprise Linux 7dnsmasqNot affected
Red Hat Enterprise Linux 8dnsmasqNot affected
Red Hat Enterprise Linux 9dnsmasqNot affected
Red Hat OpenStack Platform 13 (Queens)dnsmasqNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2048928dnsmasq: heap-based buffer overflow in resize_packet

EPSS

Процентиль: 83%
0.02519
Низкий

0 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge." However, a contributor states that a security patch (mentioned in 016162.html) is needed

CVSS3: 9.8
nvd
больше 4 лет назад

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge." However, a contributor states that a security patch (mentioned in 016162.html) is needed

CVSS3: 9.8
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 9.8
debian
больше 4 лет назад

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called ...

CVSS3: 9.8
github
больше 4 лет назад

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c).

EPSS

Процентиль: 83%
0.02519
Низкий

0 Low

CVSS3