Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2021-45954
HistoryJan 01, 2022 - 12:15 a.m.

CVE-2021-45954

2022-01-0100:15:00
Alpine Linux Development Team
security.alpinelinux.org
10
cve-2021-45954
dnsmasq
heap-based buffer overflow
extract_name
answer_auth
fuzzauth
vendor's position
real vulnerabilities
unix

EPSS

0.002

Percentile

57.6%

DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor’s position is that CVE-2021-45951 through CVE-2021-45957 “do not represent real vulnerabilities, to the best of our knowledge.”

OSVersionArchitecturePackageVersionFilename
Alpineedge-mainnoarchdnsmasq= 2.86-r2UNKNOWN
Alpine3.15-mainnoarchdnsmasq= 2.86-r1UNKNOWN
Alpine3.16-mainnoarchdnsmasq= 2.86-r2UNKNOWN