UBUNTU-CVE-2021-3448
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3448
UBUNTU-CVE-2021-3448
Summary:
Details: A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a reply and get it accepted by dnsmasq. This flaw makes a DNS Cache Poisoning attack much easier. The highest threat from this vulnerability is to data integrity.
References: https://ubuntu.com/security/CVE-2021-3448, https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2021q1/014835.html, https://ubuntu.com/security/notices/USN-4976-1, https://ubuntu.com/security/notices/USN-4976-2, https://www.cve.org/CVERecord?id=CVE-2021-3448
Affected packages
Package
Name: dnsmasq
Purl: pkg:deb/ubuntu/dnsmasq?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
