CVE-2020-25682: vulnerability in dnsmasq
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
A buffer overflow vulnerability in dnsmasq allows an attacker on the network to send specially crafted DNS replies that overflow memory and potentially execute code on the target system.
The vulnerability exists in the extract_name() function in rfc1035.c, which fails to properly validate buffer boundaries when extracting domain names from DNS packets before DNSSEC validation. An attacker with the ability to craft valid DNS replies can trigger a heap buffer overflow by providing domain names that exceed the assumed buffer size, potentially achieving remote code execution.