DNSpooq - seven new vulnerabilities in dnsmasq

Experts from JSOF research labs have reported seven new vulnerabilities in the DNS/DHCP server dnsmasq. The dnsmasq server is quite popular and is used by default in many Linux distributions, as well as in network equipment from Cisco, Ubiquiti, and others. The Dnspooq vulnerabilities include DNS cache poisoning and remote code execution. The vulnerabilities have been fixed in dnsmasq 2.83.

In 2008, renowned security researcher Dan Kaminsky discovered and disclosed a fundamental flaw in the DNS mechanism of the Internet. Kaminsky proved that attackers could spoof addresses domains and steal data. Since then, this has become known as the "Kaminsky Attack."

DNS has been considered an insecure protocol for decades, although it is supposed to ensure a certain level of integrity. This is why it is still heavily relied upon. At the same time, mechanisms for enhancing the security of the original DNS protocol have been developed. These mechanisms include HTTPS, HSTS, DNSSEC, and other initiatives. Nevertheless, even with all these mechanisms in place, DNS interception remains a significant threat in 2021. A large part of the internet still relies on DNS just as it did in 2008, making it vulnerable to the same types of attacks.

Cache poisoning vulnerabilities Dnspooq:
CVE-2020-25686, CVE-2020-25684, CVE-2020-25685. These vulnerabilities are similar to the SAD DNS attacks recently reported by researchers from the University of California and Tsinghua University. The SAD DNS and Dnspooq vulnerabilities can also be combined for even easier attacks. Additional attacks with unclear consequences have also been reported through the joint efforts of the universities (Poison Over Troubled Forwarders, etc.).
The vulnerabilities exploit reduced entropy. Due to the use of a weak hash for identifying DNS requests and inaccurate matching of requests to responses, the entropy can be significantly reduced, requiring the guessing of only about 19 bits, which enables cache poisoning. The way dnsmasq handles CNAME records allows for forging CNAME record chains and effectively poisoning up to 9 DNS records simultaneously.

Buffer overflow vulnerabilities: CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, CVE-2020-25681. All 4 identified vulnerabilities exist in the DNSSEC implementation code and only manifest when DNSSEC verification is enabled in settings.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster