Description Preview
A security vulnerability (CVE-2017-15107) was discovered in the DNSSEC implementation of Dnsmasq versions up to and including 2.78. The flaw involves the improper interpretation of wildcard synthesized NSEC (Next Secure) records, which could be exploited to prove the non-existence of hostnames that actually exist. This vulnerability could potentially allow attackers to bypass DNSSEC validation and conduct DNS spoofing attacks against systems relying on Dnsmasq for DNS resolution.
Overview
Dnsmasq is a lightweight DNS, DHCP, and TFTP server commonly used in home routers, IoT devices, and small networks. The vulnerability affects the DNSSEC validation mechanism in Dnsmasq, specifically how it handles wildcard synthesized NSEC records. DNSSEC is designed to protect against DNS spoofing by providing authentication of DNS data. However, this vulnerability undermines that protection by allowing attackers to trick Dnsmasq into believing that certain hostnames don't exist when they actually do. This could lead to DNS spoofing attacks, where users might be redirected to malicious websites or services instead of legitimate ones.
Remediation
To address this vulnerability, the following actions are recommended:
- Update Dnsmasq to version 2.79 or later, which contains the fix for this vulnerability.
- If immediate updating is not possible, consider temporarily disabling DNSSEC validation in Dnsmasq until the update can be applied (though this reduces overall security).
- Network administrators should monitor DNS traffic for any suspicious activity that might indicate exploitation attempts.
- Apply vendor-specific patches if using Dnsmasq as part of another product, such as a router firmware or Linux distribution.
- For OpenSUSE users, apply the security update referenced in openSUSE-SU-2019:2669.
References
- Vendor Advisory: http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2018q1/011896.html
- SecurityFocus: http://www.securityfocus.com/bid/102812
- OpenSUSE Security Announcement: http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00027.html
- MITRE CVE Entry: CVE-2017-15107
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Health Care & Social AssistanceHealth Care & Social Assistance
- Retail TradeRetail Trade
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Finance and InsuranceFinance and Insurance
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Public AdministrationPublic Administration
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Educational ServicesEducational Services
- Other Services (except Public Administration)Other Services (except Public Administration)
- Accommodation & Food ServicesAccommodation & Food Services
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- InformationInformation
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Wholesale TradeWholesale Trade