Описание
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.93-1 |
| esm-infra-legacy/trusty | released | 2.68-1ubuntu0.2+esm5 |
| esm-infra-legacy/xenial | released | 2.90-0ubuntu0.16.04.1+esm3 |
| esm-infra/bionic | released | 2.90-0ubuntu0.18.04.1+esm3 |
| esm-infra/focal | released | 2.90-0ubuntu0.20.04.1+esm2 |
| esm-infra/xenial | released | 2.90-0ubuntu0.16.04.1+esm3 |
| jammy | released | 2.90-0ubuntu0.22.04.3 |
| noble | released | 2.90-2ubuntu0.3 |
| questing | released | 2.91-1ubuntu0.2 |
| resolute | released | 2.92-1ubuntu0.2 |
Показывать по
EPSS
7.3 High
CVSS3
Связанные уязвимости
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
dnsmasqs extract_name() function can be abused to cause a heap buffer ...
EPSS
7.3 High
CVSS3