Количество 16
Количество 16
GHSA-xqvc-9mc9-4fgx
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.

CVE-2020-25684
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.

CVE-2020-25684
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.

CVE-2020-25684
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.

CVE-2020-25684
CVE-2020-25684
A flaw was found in dnsmasq before version 2.83. When getting a reply ...

BDU:2021-03624
Уязвимость функции reply_query() (forward.c) DNS-сервера Dnsmasq, связанная с ошибками реализации проверки безопасности для стандартных элементов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
ELSA-2021-0153
ELSA-2021-0153: dnsmasq security update (MODERATE)

openSUSE-SU-2021:0129-1
Security update for dnsmasq

openSUSE-SU-2021:0124-1
Security update for dnsmasq

SUSE-SU-2021:14604-1
Security update for dnsmasq

SUSE-SU-2021:0166-1
Security update for dnsmasq

SUSE-SU-2021:0163-1
Security update for dnsmasq

SUSE-SU-2021:0162-1
Security update for dnsmasq
ELSA-2021-0150
ELSA-2021-0150: dnsmasq security update (IMPORTANT)

SUSE-SU-2021:14603-1
Security update for dnsmasq
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-xqvc-9mc9-4fgx A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity. | CVSS3: 3.7 | 0% Низкий | больше 3 лет назад | |
![]() | CVE-2020-25684 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity. | CVSS3: 3.7 | 0% Низкий | больше 4 лет назад |
![]() | CVE-2020-25684 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity. | CVSS3: 4 | 0% Низкий | больше 4 лет назад |
![]() | CVE-2020-25684 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity. | CVSS3: 3.7 | 0% Низкий | больше 4 лет назад |
![]() | CVSS3: 3.7 | 0% Низкий | больше 4 лет назад | |
CVE-2020-25684 A flaw was found in dnsmasq before version 2.83. When getting a reply ... | CVSS3: 3.7 | 0% Низкий | больше 4 лет назад | |
![]() | BDU:2021-03624 Уязвимость функции reply_query() (forward.c) DNS-сервера Dnsmasq, связанная с ошибками реализации проверки безопасности для стандартных элементов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации | CVSS3: 3.7 | 0% Низкий | больше 4 лет назад |
ELSA-2021-0153 ELSA-2021-0153: dnsmasq security update (MODERATE) | больше 4 лет назад | |||
![]() | openSUSE-SU-2021:0129-1 Security update for dnsmasq | больше 4 лет назад | ||
![]() | openSUSE-SU-2021:0124-1 Security update for dnsmasq | больше 4 лет назад | ||
![]() | SUSE-SU-2021:14604-1 Security update for dnsmasq | больше 4 лет назад | ||
![]() | SUSE-SU-2021:0166-1 Security update for dnsmasq | больше 4 лет назад | ||
![]() | SUSE-SU-2021:0163-1 Security update for dnsmasq | больше 4 лет назад | ||
![]() | SUSE-SU-2021:0162-1 Security update for dnsmasq | больше 4 лет назад | ||
ELSA-2021-0150 ELSA-2021-0150: dnsmasq security update (IMPORTANT) | больше 4 лет назад | |||
![]() | SUSE-SU-2021:14603-1 Security update for dnsmasq | больше 4 лет назад |
Уязвимостей на страницу