Origin validation error in Dnsmasq - CVE-2005-0877

 

Origin validation error in Dnsmasq - CVE-2005-0877

Published: February 8, 2024 / Updated: June 8, 2025


Vulnerability identifier: #VU110638
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2005-0877
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.


Affected software

Dnsmasq

How to mitigate CVE-2005-0877

Install update from vendor's website.

Dnsmasq - update to 2.21

External References

Related Security Bulletins