Bug 22494 - dnsmasq new security issue CVE-2017-15107
Summary: dnsmasq new security issue CVE-2017-15107
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Julien Moragny
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-01-31 03:29 CET by David Walser
Modified: 2018-02-01 00:26 CET (History)
0 users

See Also:
Source RPM: dnsmasq-2.77-1.2.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-01-31 03:29:06 CET
Fedora has issued an advisory today (January 30):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UQBQNMDMDJKU5GDXPKGPK5EWI5VQWYC6/

Mageia 5 and Mageia 6 would also be affected if Cauldron is.

Not affected are builds without DNSSEC support.  I don't know whether ours is.
David Walser 2018-01-31 03:29:29 CET

Whiteboard: (none) => MGA6TOO

Comment 1 Julien Moragny 2018-01-31 21:46:03 CET
Hello,

mga5 & 6 aren't built with dnssec support so they should not be affected.

I just submitted dnsmasq 2.78-3 with the patches to fix this CVE (and correct the packaging to really allow dnssec to work).

regards
Julien
Comment 2 David Walser 2018-02-01 00:26:06 CET
Thanks Julien!

Resolution: (none) => FIXED
Status: NEW => RESOLVED
Whiteboard: MGA6TOO => (none)


Note You need to log in before you can comment on or make changes to this bug.