CVE-2020-25683: vulnerability in dnsmasq
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
A flaw in dnsmasq allows remote attackers to crash the service by sending specially crafted DNS replies when DNSSEC is enabled. This happens because the software doesn't properly check the length of data before copying it in memory, leading to a crash that prevents DNS lookups from working.
A heap-based buffer overflow exists in dnsmasq's rfc1035.c extract_name() function due to missing length validation. An unauthenticated remote attacker can exploit this by sending malformed DNS responses when DNSSEC validation is active, triggering memcpy() with invalid size parameters and causing denial of service through process termination.