First published: Tue Jan 23 2018(Updated: )
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thekelleys Dnsmasq | <=2.78 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dnsmasq vulnerability is CVE-2017-15107.
The severity of CVE-2017-15107 is high with a score of 7.5.
The affected software for CVE-2017-15107 is Dnsmasq up to and including version 2.78.
The vulnerability can be exploited by synthesizing wildcard NSEC records in DNSSEC to prove the non-existence of hostnames that actually exist.
Yes, a fix for CVE-2017-15107 is available. It is recommended to update to a version of Dnsmasq that is not affected by this vulnerability.