SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-25682

A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data.

HIGH 8.1EPSS 70.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 70.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use this flaw to cause an overflow with arbitrary data in a heap-allocated memory, possibly executing code on the machine. The flaw is in the rfc1035.c:extract_name() function, which writes data to the memory pointed by name assuming MAXDNAME*2 bytes are available in the buffer. However, in some code execution paths, it is possible extract_name() gets passed an offset from the base buffer, thus reducing, in practice, the number of available bytes that can be written in the buffer. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
70.75% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-122, CWE-787
Affected
thekelleys/dnsmasq · fedoraproject/fedora · debian/debian linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.