{"id":"MGASA-2020-0310","summary":"Updated dnsmasq packages fix security vulnerability","details":"Updated dnsmasq package fix insecure default configuration potentially\nmaking it an open resolver (CVE-2020-14312).\n\nIn its default configuration, dnsmasq listen and answer query from any\naddress even outside of the local subnet. Thus, it may inadvertently\nbecome an open resolver which might be used in Distributed Denial of\nService attacks.\n\nThis update add the option --local-service at startup which limits\ndnsmasq to listen only to machines on the same local network.\n\nThis option only works if there aren't any of the following options\non cmdline or in dnsmasq.conf (without the double dash):\n--interface\n--except-interface\n--listen-address\n--auth-server\n","modified":"2026-04-16T04:43:32.210513536Z","published":"2020-07-31T23:25:42Z","upstream":["CVE-2020-14312"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0310.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26964"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1851342"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1852373"}],"affected":[{"package":{"name":"dnsmasq","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/dnsmasq?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.80-5.3.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0310.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}