RHSA-2008:0789: Moderate: dnsmasq security update
Dnsmasq is lightweight DNS forwarder and DHCP server. It is designed toprovide DNS and, optionally, DHCP, to a small network.The dnsmasq DNS resolver used a fixed source UDP port. This could have madeDNS spoofing attacks easier. dnsmasq has been updated to use random UDPsource ports, helping to make DNS spoofing attacks harder. (CVE-2008-1447)All dnsmasq users are advised to upgrade to this updated package, thatupgrades dnsmasq to version 2.45, which resolves this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0789?
The severity of RHSA-2008:0789 is classified as moderate.
How do I fix RHSA-2008:0789?
To fix RHSA-2008:0789, update dnsmasq to version 2.45-1.el5_2.1 or later.
What systems are affected by RHSA-2008:0789?
RHSA-2008:0789 affects dnsmasq versions earlier than 2.45-1.el5_2.1 on Red Hat Enterprise Linux.
What vulnerability does RHSA-2008:0789 address?
RHSA-2008:0789 addresses a vulnerability related to using a fixed source UDP port in the dnsmasq DNS resolver, which could facilitate DNS spoofing.
Is it safe to continue using dnsmasq without addressing RHSA-2008:0789?
Continuing to use dnsmasq without addressing RHSA-2008:0789 can expose the system to potential DNS spoofing attacks.