ELSA-2024-1335

ELSA-2024-1335 - dnsmasq security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2024-03-15

Description


[2.79-31.2]
- Fix CVE 2023-50387 and CVE 2023-50868
- Resolves: RHEL-25628
- Resolves: RHEL-25666

[2.79-31.1]
- Do not crash on invalid domain in --synth-domain option (RHEL-22741)

[2.79-31]
- Do not create and search --local and --address=/x/# domains (#2233542)

[2.79-30]
- Make create logfile writeable by root (#2156789)

[2.79-29]
- Fix also dynamically set resolvers over dbus (#2186481)

[2.79-28]
- Correct possible crashes when server=/example.net/# is used (#2186481)

[2.79-27]
- Limit offered EDNS0 size to 1232 (CVE-2023-28450)


Related CVEs


CVE-2023-50387
CVE-2023-50868

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) dnsmasq-2.79-31.el8_9.2.src.rpm1ac4a307fa23a2c512c77ade4a2d6352-ol8_aarch64_appstream
dnsmasq-2.79-31.el8_9.2.aarch64.rpm1a30f4630f2249761b022008477e0e5b-ol8_aarch64_appstream
dnsmasq-utils-2.79-31.el8_9.2.aarch64.rpmbdcbd5aa914f18782c7a07f5f353bdfd-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) dnsmasq-2.79-31.el8_9.2.src.rpm1ac4a307fa23a2c512c77ade4a2d6352-ol8_x86_64_appstream
dnsmasq-2.79-31.el8_9.2.x86_64.rpm00d6622797479ee17241aa22739c9952-ol8_x86_64_appstream
dnsmasq-utils-2.79-31.el8_9.2.x86_64.rpmd903ad2d01d2e6d0e0a96721a5728091-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete