Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29044
HistoryJan 20, 2021 - 4:41 p.m.

Arbitrary Code Execution

2021-01-2016:41:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.085 Low

EPSS

Percentile

94.5%

dnsmasq is vulnerable to arbitrary code execution. A heap-based buffer overflow in rfc1035.c:extract_name() due to the lack of length checks, which could be abused occurs when DNSSEC is enabled and before the receiving DNS entries are validated. A remote attacker who can create valid DNS replies is able to exploit the vulnerability execute arbitrary code via memcpy() using negative size in sort_rrset().