CVE-2017-15107: High severity dnsmasq vulnerability
Published Jan 23, 2018
·Updated
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
Affected Software
1 affected component
thekelleys dnsmasq<=2.78
Event History
Jan 23, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Dnsmasq vulnerability?
The vulnerability ID for this Dnsmasq vulnerability is CVE-2017-15107.
2
What is the severity of CVE-2017-15107?
The severity of CVE-2017-15107 is high with a score of 7.5.
3
What is the affected software for CVE-2017-15107?
The affected software for CVE-2017-15107 is Dnsmasq up to and including version 2.78.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by synthesizing wildcard NSEC records in DNSSEC to prove the non-existence of hostnames that actually exist.
5
Is there a fix available for CVE-2017-15107?
Yes, a fix for CVE-2017-15107 is available. It is recommended to update to a version of Dnsmasq that is not affected by this vulnerability.