
Cloud Vulnerability DB
A community-led vulnerabilities database
A flaw was discovered in dnsmasq before version 2.83 (CVE-2020-25684). When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply (NVD, Red Hat Bugzilla).
The vulnerability has a CVSS v3.1 Base Score of 3.7 (LOW) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N. The flaw is related to how dnsmasq handles reply queries, specifically in the forward.c:reply_query() function. The vulnerability stems from insufficient validation of address/port information when processing DNS replies, making it easier for attackers to forge DNS responses (NVD, Arista Advisory).
This vulnerability allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity. The vulnerability could lead to invalid DNS records being served to clients querying the affected DNS server (NVD, Arista Advisory).
The vulnerability requires network access and high attack complexity to exploit. No authentication or user interaction is required. The vulnerability is part of a collection of vulnerabilities known as 'DNSPooq'. To be exploitable, the device must be acting as a DNS server accessible to external devices (Arista Advisory).
The primary mitigation is to upgrade to dnsmasq version 2.83 or later. For systems where immediate upgrade is not feasible, the impact can be reduced by disabling the dnsmasq cache by adding 'cache-size=0' to the dnsmasq configuration file. However, disabling the cache may result in performance loss due to all DNS queries being forwarded to upstream servers (Red Hat Bugzilla).
The vulnerability was discovered by Moshe Kol and Shlomi Oberman of JSOF. It was part of a coordinated disclosure effort with CERT and dnsmasq, known as the 'DNSPooq' vulnerability set. Multiple vendors including Red Hat, Debian, Fedora, and Arista Networks have released security advisories and patches for their affected products (JSOF, Debian Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."