Vulnerability CVE-2023-28450: Information

Description

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: March 16, 2023
Modified: Nov. 7, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
dnsmasqsisyphus2.89-alt22.90-alt1ALT-PU-2023-1523-1317626Fixed
dnsmasqsisyphus_e2k2.89-alt22.90-alt1ALT-PU-2023-2995-1-Fixed
dnsmasqsisyphus_riscv642.89-alt22.90-alt1ALT-PU-2023-3000-1-Fixed
dnsmasqsisyphus_loongarch642.90-alt12.90-alt1ALT-PU-2024-2725-1-Fixed
dnsmasqp102.89-alt22.90-alt1ALT-PU-2023-1548-1317627Fixed
dnsmasqp10_e2k2.89-alt22.90-alt1ALT-PU-2023-3098-1-Fixed
dnsmasqp92.85-alt2.p9.12.85-alt2.p9.1ALT-PU-2023-8012-2336361Fixed
dnsmasqc10f12.90-alt12.90-alt1ALT-PU-2024-3156-3341618Fixed
dnsmasqc9f22.89-alt22.90-alt1ALT-PU-2023-1570-1317629Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:*
      End excliding
      2.90