CVE-2020-25681
high-risk
Published 2021-01-20
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as that they are accepted as valid, could use this flaw to cause a buffer overflow with arbitrary data in a heap memory segment, possibly executing code on the machine. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Do I need to act?
!
45.4% chance of exploitation in next 30 days
EPSS score — higher than 55% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.1/10
High
NETWORK
/ HIGH complexity
Affected Products (5)
Affected Vendors
References (15)
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1881875
Third Party Advisory
https://security.gentoo.org/glsa/202101-17
Third Party Advisory
https://www.debian.org/security/2021/dsa-4844
Third Party Advisory
https://www.jsof-tech.com/disclosures/dnspooq/
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1881875
Third Party Advisory
https://security.gentoo.org/glsa/202101-17
Third Party Advisory
https://www.debian.org/security/2021/dsa-4844
Third Party Advisory
https://www.jsof-tech.com/disclosures/dnspooq/
53
/ 100
high-risk
Severity
24/34 · High
Exploitability
17/34 · Moderate
Exposure
12/34 · Low