{"id":"SUSE-SU-2021:14603-1","summary":"Security update for dnsmasq","details":"This update for dnsmasq fixes the following issues:\n\n- CVE-2019-14834: Fixed a memory leak which could have allowed to remote attackers \n  to cause denial of service via DHCP response creation (bsc#1154849)\n- bsc#1177077: Fixed DNSpooq vulnerabilities\n- CVE-2020-25684, CVE-2020-25685, CVE-2020-25686:\n  Fixed multiple Cache poisoning attacks.\n- CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687:\n  Fixed multiple potential Heap-based overflows when DNSSEC is\n  enabled.\n- Retry query to other servers on receipt of SERVFAIL rcode\n  (bsc#1176076)\n","modified":"2026-02-04T02:44:37.249400Z","published":"2021-01-19T11:11:40Z","related":["CVE-2019-14834","CVE-2020-25681","CVE-2020-25682","CVE-2020-25683","CVE-2020-25684","CVE-2020-25685","CVE-2020-25686","CVE-2020-25687"],"upstream":["CVE-2019-14834","CVE-2020-25681","CVE-2020-25682","CVE-2020-25683","CVE-2020-25684","CVE-2020-25685","CVE-2020-25686","CVE-2020-25687"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-202114603-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154849"},{"type":"REPORT","url":"https://bugzilla.suse.com/1176076"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177077"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-14834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25682"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25686"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25687"}],"affected":[{"package":{"name":"dnsmasq","ecosystem":"SUSE:Linux Enterprise Server 11 SP4-LTSS","purl":"pkg:rpm/suse/dnsmasq&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.78-0.17.15.1"}]}],"ecosystem_specific":{"binaries":[{"dnsmasq":"2.78-0.17.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:14603-1.json"}}],"schema_version":"1.7.3"}