VDB
MAGEIA-2021-231
MAGEIA-2021-231
PUBLISHED
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a reply and get it accepted by dnsmasq. This flaw makes a DNS Cache Poisoning attack much easier (CVE-2021-3448). This kind of configuration is the default when network-manager uses dnsmasq.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | perl-URPM | 0, 5.222-1.mga8 |
| Mageia | dnsmasq | 0, 0, 2.85-1.mga7 |
| Mageia | dnsmasq | 2.85-1.mga8, 0, 0 |
Timeline
- Jun 7, 2021 CVE Updated
- Jun 8, 2021 CVE Published
References
- Updated dnsmasq packages fix a security vulnerability advisory
- Updated dnsmasq packages fix a security vulnerability issue
- Updated dnsmasq packages fix a security vulnerability issue
- Updated dnsmasq packages fix a security vulnerability issue
- Updated perl-URPM packages fixes bugs advisory
- Updated perl-URPM packages fixes bugs issue