Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1000135
HistoryMar 20, 2018 - 3:49 p.m.

CVE-2018-1000135

2018-03-2015:49:18
redhat.com
access.redhat.com
10

EPSS

0.003

Percentile

69.9%

An information exposure vulnerability has been found in NetworkManager when dnsmasq is used in DNS processing mode. An attacker in control of a DNS server could receive DNS queries even though a Virtual Private Network (VPN) was configured on the vulnerable machine.

Mitigation

We suggest to keep the default dns=default in the NetworkManager configuration file to prevent DNS queries leaks to possibly hostile DNS servers.