Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2021-45955
HistoryDec 31, 2021 - 11:53 p.m.

CVE-2021-45955

2021-12-3123:53:42
mitre
github.com
4
dnsmasq 2.86
heap-based buffer overflow
bounds check
security patch

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

57.6%

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

total

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor’s position is that CVE-2021-45951 through CVE-2021-45957 “do not represent real vulnerabilities, to the best of our knowledge.” However, a contributor states that a security patch (mentioned in 016162.html) is needed

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

57.6%

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

total