Use of a broken or risky cryptographic algorithm in Dnsmasq - CVE-2020-25685

 

Use of a broken or risky cryptographic algorithm in Dnsmasq - CVE-2020-25685

Published: January 20, 2021 / Updated: January 24, 2021


Vulnerability identifier: #VU49844
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25685
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a lack of query resource name (RRNAME) checks in the "reply_query" function. A remote attacker can perform a DNS cache poisoning attack.


Affected software

Dnsmasq
Arch Linux
Gentoo Linux
ArubaOS (AOS)
F5OS
Red Hat Enterprise Linux for IBM System z (Structure A)
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Slackware Linux
Ubuntu
openEuler
Fedora
QuTScloud
Arista Extensible Operating System (EOS)
Aruba Mobility Controller
Data Computing Appliance (DCA)
cockpit-ovirt (Red Hat package)
imgbased (Red Hat package)
dnsmasq (Debian package)
sssd (Red Hat package)
dnsmasq (Alpine package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
vdsm (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dnsmasq (Red Hat package)
dnsmasq-utils (Ubuntu package)
dnsmasq-base (Ubuntu package)
dnsmasq (Ubuntu package)
dnsmasq-debuginfo
dnsmasq
dnsmasq-debugsource
dnsmasq-help
AWK-1137C Series
AWK-4131A
AWK-1131A Series
QuTS hero
AWK-3131A Series
Remote Ethernet Device (SD-RED)
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat Virtualization Host
Sophos UTM
Sophos Firewall
QNAP QTS

How to mitigate CVE-2020-25685

Install updates from vendor's website.

Dnsmasq - update to 2.83
cockpit-ovirt (Red Hat package) - update to 0.14.17-1.el8ev
imgbased (Red Hat package) - update to 1.2.16-0.1.el8ev
AWK-1137C Series - update to 1.7
AWK-3131A Series - update to 1.17
AWK-4131A - update to 1.17
AWK-1131A Series - update to 1.23
dnsmasq (Debian package) - update to 2.80-1+deb10u1
sssd (Red Hat package) - update to 2.3.0-9.el8
dnsmasq (Alpine package) - update to 2.83-r0
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.13-2.el7ev, 4.4.4-1.el8ev
redhat-virtualization-host (Red Hat package) - addressed in versions 4.3.13-20210127.0.el7_9, 4.4.4-20210201.0.el8_3
vdsm (Red Hat package) - update to 4.30.51-1.el7ev
Sophos UTM - update to 9.706
Sophos Firewall - addressed in versions 17.5.15, 18.0.4
QuTS hero - update to h4.5.3.1670 build 20210515
dnsmasq (Red Hat package) - addressed in versions 2.66-14.el7_2.3, 2.66-21.el7_3.3, 2.76-2.el7_4.3, 2.76-7.el7_6.2, 2.76-10.el7_7.2, 2.76-16.el7_9.1, 2.79-6.el8_1.1, 2.79-11.el8_2.2, 2.79-13.el8_3.1
dnsmasq-utils (Ubuntu package) - addressed in versions 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq-base (Ubuntu package) - addressed in versions 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq (Ubuntu package) - addressed in versions 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq-debuginfo - update to 2.82-4
dnsmasq - update to 2.82-4
dnsmasq-debugsource - update to 2.82-4
dnsmasq-help - update to 2.82-4
dnsmasq - addressed in versions 2.83-1.fc33, 2.84-1.fc32
Remote Ethernet Device (SD-RED) - update to 3.0.004
Data Computing Appliance (DCA) - update to 4.3.0.0
QuTScloud - update to 4.5.3.1652 20210428
QNAP QTS - update to 4.5.3.1652 20210428
Arista Extensible Operating System (EOS) - addressed in versions 4.21.14M, 4.22.9M, 4.23.7M, 4.24.5M, 4.25.2F

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins