Lucene search

K
ubuntuUbuntuUSN-6657-1
HistoryFeb 26, 2024 - 12:00 a.m.

Dnsmasq vulnerabilities

2024-02-2600:00:00
ubuntu.com
84
dnsmasq
ubuntu
dnssec
nsec3
denial of service
cve-2023-50387
cve-2023-50868
cve-2023-28450

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.05

Percentile

93.0%

Releases

  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • dnsmasq - Small caching DNS proxy and DHCP/TFTP server

Details

Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Dnsmasq icorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Dnsmasq to consume
resources, leading to a denial of service. (CVE-2023-50387)

It was discovered that Dnsmasq incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Dnsmasq to consume resources, leading to a denial of service.
(CVE-2023-50868)

It was discovered that Dnsmasq incorrectly set the maximum EDNS.0 UDP
packet size as required by DNS Flag Day 2020. This issue only affected
Ubuntu 23.10. (CVE-2023-28450)

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchdnsmasq-base< 2.90-0ubuntu0.23.10.1UNKNOWN
Ubuntu23.10noarchdnsmasq< 2.90-0ubuntu0.23.10.1UNKNOWN
Ubuntu23.10noarchdnsmasq-base-lua< 2.90-0ubuntu0.23.10.1UNKNOWN
Ubuntu23.10noarchdnsmasq-utils< 2.90-0ubuntu0.23.10.1UNKNOWN
Ubuntu22.04noarchdnsmasq-base< 2.90-0ubuntu0.22.04.1UNKNOWN
Ubuntu22.04noarchdnsmasq< 2.90-0ubuntu0.22.04.1UNKNOWN
Ubuntu22.04noarchdnsmasq-base-lua< 2.90-0ubuntu0.22.04.1UNKNOWN
Ubuntu22.04noarchdnsmasq-utils< 2.90-0ubuntu0.22.04.1UNKNOWN
Ubuntu20.04noarchdnsmasq-base< 2.90-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchdnsmasq< 2.90-0ubuntu0.20.04.1UNKNOWN
Rows per page:
1-10 of 121

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.05

Percentile

93.0%