CVE-2020-14312
Last modified
CVE-2020-14312 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any address on the internet. This flaw allows an attacker to conduct a Distributed Denial of Service (DDoS) against other systems.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fedoraproject | Fedora | < 31 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1851342Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1851342Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-14312?
How severe is CVE-2020-14312?
How do I fix CVE-2020-14312?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-14307A vulnerability was found in Wildfly's Enterprise Java Beans…6.5
- CVE-2020-14308In grub2 versions before 2.06 the grub memory allocator does…6.4
- CVE-2020-14309There's an issue with grub2 in all versions before 2.06 when…6.7
- CVE-2020-1431An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-14310There is an issue on grub2 before version 2.06 at function r…6
- CVE-2020-14311There is an issue with grub2 before version 2.06 while handl…6
- CVE-2020-14313An information disclosure vulnerability was found in Red Hat…4.3
- CVE-2020-14314A memory out-of-bounds read flaw was found in the Linux kern…5.5
- CVE-2020-14315A memory corruption vulnerability is present in bspatch as s…9.8
- CVE-2020-14316A flaw was found in kubevirt 0.29 and earlier. Virtual Machi…9.9
- CVE-2020-14317It was found that the issue for security flaw CVE-2019-3805 …5.5
- CVE-2020-14318A flaw was found in the way samba handled file and directory…4.3
Are you affected by CVE-2020-14312?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
