LWN.net Logo

dnsmasq: access restriction bypass

Package(s):dnsmasq CVE #(s):CVE-2013-0198
Created:February 7, 2013 Updated:February 18, 2013
Description:

From the Mageia advisory:

This update completes the fix for CVE-2012-3411 provided with dnsmasq-2.63. It was found that after the upstream patch for CVE-2012-3411 issue was applied, dnsmasq still:

- replied to remote TCP-protocol based DNS queries (UDP protocol ones were corrected, but TCP ones not) from prohibited networks, when the --bind-dynamic option was used,

- when --except-interface lo option was used dnsmasq didn't answer local or remote UDP DNS queries, but still allowed TCP protocol based DNS queries,

- when --except-interface lo option was not used local / remote TCP DNS queries were also still answered by dnsmasq.

Alerts:
Mageia MGASA-2013-0030 2013-02-06
Fedora FEDORA-2013-1357 2013-02-12
Fedora FEDORA-2013-1320 2013-02-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds