Summary: | <net-dns/dnsmasq-2.66: Incomplete fix for the CVE-2012-3411 issue (CVE-2013-0198) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | alex_y_xu, chutzpah |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2013/01/18/2 | ||
Whiteboard: | B3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2013-01-20 13:31:28 UTC
CVE-2013-0198 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0198): Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411. I will pull in 2.66 final when it comes out with the fix, unless someone submits a separated patch that applies against 2.65. net-dns/dnsmasq-2.66 is now in the tree containing the fix for this (In reply to comment #3) > net-dns/dnsmasq-2.66 is now in the tree containing the fix for this And ready to go stable? Yeah it's ready to go stable. Sorry about the delay in responding here. Arches, please test and mark stable: =net-dns/dnsmasq-2.66 Target KEYWORDS: "alpha amd64 arm hppa ia64 ~mips ppc ppc64 s390 sh sparc x86 ~sparc-fbsd ~x86-fbsd" Stable for HPPA. amd64 stable x86 stable alpha stable arm stable ia64 stable ppc64 stable ppc stable sparc stable s390 stable sh stable GLSA vote: yes Poke, 8 months passed. GLSA Vote: Yes Created a New GLSA request. This issue was resolved and addressed in GLSA 201406-24 at http://security.gentoo.org/glsa/glsa-201406-24.xml by GLSA coordinator Mikle Kolyada (Zlogene). |