Dnsmasq Security Restriction Bypass Vulnerability (CVE-2017-15107)
Dnsmasq Security Restriction Bypass Vulnerability (CVE-2017-15107)
Release date:
Updated on:
Affected Systems:
Dnsmasq <= 2.78
Description:
Bugtraq id: 102812
CVE (CAN) ID: CVE-2017-15107
Dnsmasq is a lightweight DNS forwarder and DHCP server.
Dnsmasq 2.78 and earlier versions have security vulnerabilities in DNSSEC. After successful exploitation, attackers can bypass certain security restrictions and perform unauthorized operations.
<* Source: Ralph Dolmans
*>
Suggestion:
Vendor patch:
Dnsmasq
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2018q1/011896.html
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1510570
Https://access.redhat.com/security/cve/cve-2017-15107
Http://www.thekelleys.org.uk/dnsmasq/doc.html
Http://thekelleys.org.uk/gitweb? P = dnsmasq. git; a = commitdiff; h = 4fe6744a220eddd3f1749b40cac3dfc510787de6