Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202101-17 ] Dnsmasq: Multiple vulnerabilities
Date: Fri, 22 Jan 2021 18:00:46
Message-Id: YAsRyBrsuSLQjjAH@samurai
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202101-17
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Dnsmasq: Multiple vulnerabilities
9 Date: January 22, 2021
10 Bugs: #766126
11 ID: 202101-17
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Dnsmasq, the worst of which
19 may allow remote attackers to execute arbitrary code.
20
21 Background
22 ==========
23
24 Dnsmasq is a lightweight and easily-configurable DNS forwarder and DHCP
25 server.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-dns/dnsmasq < 2.83 >= 2.83
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Dnsmasq. Please review
39 the references below for details.
40
41 Impact
42 ======
43
44 An attacker, by sending specially crafted DNS replies, could possibly
45 execute arbitrary code with the privileges of the process, perform a
46 cache poisoning attack or cause a Denial of Service condition.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Dnsmasq users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=net-dns/dnsmasq-2.83"
60
61 References
62 ==========
63
64 [ 1 ] CVE-2020-25681
65 https://nvd.nist.gov/vuln/detail/CVE-2020-25681
66 [ 2 ] CVE-2020-25682
67 https://nvd.nist.gov/vuln/detail/CVE-2020-25682
68 [ 3 ] CVE-2020-25683
69 https://nvd.nist.gov/vuln/detail/CVE-2020-25683
70 [ 4 ] CVE-2020-25684
71 https://nvd.nist.gov/vuln/detail/CVE-2020-25684
72 [ 5 ] CVE-2020-25685
73 https://nvd.nist.gov/vuln/detail/CVE-2020-25685
74 [ 6 ] CVE-2020-25686
75 https://nvd.nist.gov/vuln/detail/CVE-2020-25686
76 [ 7 ] CVE-2020-25687
77 https://nvd.nist.gov/vuln/detail/CVE-2020-25687
78
79 Availability
80 ============
81
82 This GLSA and any updates to it are available for viewing at
83 the Gentoo Security Website:
84
85 https://security.gentoo.org/glsa/202101-17
86
87 Concerns?
88 =========
89
90 Security is a primary focus of Gentoo Linux and ensuring the
91 confidentiality and security of our users' machines is of utmost
92 importance to us. Any security concerns should be addressed to
93 security@g.o or alternatively, you may file a bug at
94 https://bugs.gentoo.org.
95
96 License
97 =======
98
99 Copyright 2021 Gentoo Foundation, Inc; referenced text
100 belongs to its owner(s).
101
102 The contents of this document are licensed under the
103 Creative Commons - Attribution / Share Alike license.
104
105 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature