Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29042
HistoryJan 20, 2021 - 4:41 p.m.

Information Disclosure

2021-01-2016:41:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.012 Low

EPSS

Percentile

85.0%

dnsmasq is vulnerable to information disclosure. The vulnerability exists because when getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq.