dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
| Vendor | Product | Versions |
|---|---|---|
| dnsmasq | dnsmasq | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| debian | debian linux | cert_advisory | 90% |
| open source | dnsmasq | cert_advisory | 90% |
Added technical detail about remote code execution (RCE) exploitation capability demonstrated on OpenWRT targets with malicious upstream DNS servers.
Updated affected versions to 2.92rel2, added patch availability for 2.92rel2, added CWE-120, set exploitAvailable to true, added MITRE ATT&CK technique T1560.001, and added tags 'dns', 'heap-overflow', and 'dos'.
Updated description with new technical details, changed severity to CRITICAL, and added affected version 2.92rel2.
Initial creation