Name | CVE-2017-15107 |
Description | A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 888200 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
dnsmasq (PTS) | buster, buster (security) | 2.80-1+deb10u1 | fixed |
bullseye | 2.85-1 | fixed | |
bookworm, sid | 2.89-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
dnsmasq | source | (unstable) | 2.79-1 | 888200 |
[stretch] - dnsmasq <no-dsa> (Minor issue)
[jessie] - dnsmasq <no-dsa> (Minor issue)
[wheezy] - dnsmasq <no-dsa> (Minor issue)
http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2018q1/011896.html
https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=4fe6744a220eddd3f1749b40cac3dfc510787de6
https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=cd7df612b14ec1bf831a966ccaf076be0dae7404
https://medium.com/nlnetlabs/the-peculiar-case-of-nsec-processing-using-expanded-wildcard-records-ae8285f236be