Oval Definition:oval:com.redhat.rhsa:def:20210150
Revision Date:2021-01-19Version:637
Title:RHSA-2021:0150: dnsmasq security update (Important)
Description:The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.

Security Fix(es):

  • dnsmasq: heap-based buffer overflow in sort_rrset() when DNSSEC is enabled (CVE-2020-25681)

  • dnsmasq: buffer overflow in extract_name() due to missing length check when DNSSEC is enabled (CVE-2020-25682)

  • dnsmasq: heap-based buffer overflow with large memcpy in get_rdata() when DNSSEC is enabled (CVE-2020-25683)

  • dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25684)

  • dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25685)

  • dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker (CVE-2020-25686)

  • dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset() when DNSSEC is enabled (CVE-2020-25687)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2020-25681
    CVE-2020-25682
    CVE-2020-25683
    CVE-2020-25684
    CVE-2020-25685
    CVE-2020-25686
    CVE-2020-25687
    RHSA-2021:0150
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • dnsmasq is earlier than 0:2.79-13.el8_3.1
  • AND dnsmasq is signed with Red Hat redhatrelease2 key
  • dnsmasq-utils is earlier than 0:2.79-13.el8_3.1
  • AND dnsmasq-utils is signed with Red Hat redhatrelease2 key
  • BACK