CVE-2020-25681 Details
Description
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as that they are accepted as valid, could use this flaw to cause a buffer overflow with arbitrary data in a heap memory segment, possibly executing code on the machine. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| thekelleys dnsmasq | < 2.83 |
CPE
Remediation
| |
| fedoraproject fedora | 32 33 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Mar 26, 2021 | Modified Analysis | [email protected] |
| Mar 22, 2021 | CVE Modified | [email protected] |
| Feb 25, 2021 | Modified Analysis | [email protected] |
| Feb 20, 2021 | CVE Modified | [email protected] |
| Feb 8, 2021 | Modified Analysis | [email protected] |
| Feb 4, 2021 | CVE Modified | [email protected] |
| Jan 28, 2021 | Initial Analysis | [email protected] |
| Jan 26, 2021 | CVE Modified | [email protected] |