<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>231282</bug_id>
          
          <creation_ts>2008-07-09 10:48 0000</creation_ts>
          <short_desc>net-dns/dnsmasq possibly affected by cache poisoning issue VU#800113 ?</short_desc>
          <delta_ts>2008-09-04 20:12:33 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2008q3/002147.html</bug_file_loc>
          <status_whiteboard>?? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>vorlon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>arm@gentoo.org</cc>
    
    <cc>chutzpah@gentoo.org</cc>
    
    <cc>holger.hoffstaette@googlemail.com</cc>
    
    <cc>matt@xerq.net</cc>
    
    <cc>s390@gentoo.org</cc>
    
    <cc>sh@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-07-09 10:48:49 0000</bug_when>
            <thetext>dnsmasq is probably affected by the cache poisoning issues too, see $URL</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chutzpah@gentoo.org</who>
            <bug_when>2008-07-09 18:25:50 0000</bug_when>
            <thetext>Yes, it does appear to be affected, I will update the version in portage as soon as a fix is out.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chutzpah@gentoo.org</who>
            <bug_when>2008-07-09 21:49:00 0000</bug_when>
            <thetext>comitted net-dns/dnsmasq-2.43_rc3 which should have the fix (although it is unclear if dnsmasq is affected)

http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2008q3/002148.html</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>matt@xerq.net</who>
            <bug_when>2008-07-10 00:40:11 0000</bug_when>
            <thetext>I&apos;ve tested both versions. I noticed that in the recently committed version that dnsmasq doesn&apos;t leave a high numbered UDP port open (in my case it was 32781)

output of netstat -an | grep udp

Version 2.42:
udp        0      0 0.0.0.0:32781           0.0.0.0:*                           
udp        0      0 0.0.0.0:53              0.0.0.0:*                           

Version 2.43rc3:                 
udp        0      0 0.0.0.0:53              0.0.0.0:*                           
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-07-11 14:50:04 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=net-dns/dnsmasq-2.43
Target keywords : &quot;alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-07-11 15:22:16 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chutzpah@gentoo.org</who>
            <bug_when>2008-07-11 15:26:34 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>bluebird@gentoo.org</who>
            <bug_when>2008-07-11 15:50:38 0000</bug_when>
            <thetext>sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-07-11 16:22:53 0000</bug_when>
            <thetext>alpha/ia64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-07-12 14:24:21 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-07-13 17:25:46 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-07-13 19:25:24 0000</bug_when>
            <thetext>Since bind got a GLSA, I guess we&apos;ll have another one, but maybe we should combine with other DNS resolvers? Anyway, glsa reques filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-09-04 20:12:33 0000</bug_when>
            <thetext>GLSA 200809-02</thetext>
          </long_desc>
      
    </bug>

</bugzilla>