Vulnerability CVE-2021-3448: Information

Description

A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a reply and get it accepted by dnsmasq. This flaw makes a DNS Cache Poisoning attack much easier. The highest threat from this vulnerability is to data integrity.

Severity: MEDIUM (4.0) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Published: April 9, 2021
Modified: Nov. 7, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
dnsmasqsisyphus2.85-alt12.90-alt1ALT-PU-2021-1622-1269273Fixed
dnsmasqp102.85-alt12.90-alt1ALT-PU-2021-1622-1269273Fixed
dnsmasqp92.85-alt12.85-alt2.p9.1ALT-PU-2021-1638-1269274Fixed
dnsmasqc10f12.85-alt12.90-alt1ALT-PU-2021-1622-1269273Fixed
dnsmasqc9f22.85-alt12.90-alt1ALT-PU-2021-1645-1269275Fixed
dnsmasqp112.85-alt12.90-alt1ALT-PU-2021-1622-1269273Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:*
      End excliding
      2.85

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.9.0:*:*:*:*:*:*:*