- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Sticky This Topic
- Bookmark
- Subscribe
- Printer Friendly Page
dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-02-2017 09:23 AM
Google dropped 7 CVEs on dnsmasq today, three with remote code execution.
https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-02-2017 11:12 AM
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-02-2017 02:34 PM
NOOT NOOT please fix this.
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-02-2017 04:19 PM
@UBNT-afomins @UBNT-ancheng is there an ETA for 1.9.7.hotfix.4 with an updated dnsmasq binary patched against these CVEs, especially with at least one having a remote code exploit and dnsmasq potentially being open to "insecure" networks in certain configurations?
Rated CRITICAL:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14491
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14492
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14493
Rated IMPORTANT:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13704
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14494
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14495
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14496
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 12:16 AM
+1 . Please be on top of security issues like this!
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 03:08 AM
you can add those september 2017 openvpn vulns
https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 05:13 AM
Feature Request: RFC 6296 (IPv6 to IPv6 Npt)
Unbound for DNS
DUID-EN Support
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 07:28 AM
Please post updates for the edgerouter -- I've got a network to run here!
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 07:52 AM
Check here https://community.ubnt.com/t5/EdgeMAX/dnscrypt-proxy-DNSSEC-and-dnsmasq-on-Edgerouter-Lite/m-p/19116... for a member-contributed build of v2.78. (Second post down, I think.)
May help in the interm, until UBNT can compile and release an official hotfix.
-AJ
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 09:15 AM
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 09:22 AM
I find it interesting that they would post that to reddit, but not their own forum.
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 09:39 AM
@aweber They wrote it is being worked on in the other thread: https://community.ubnt.com/t5/UniFi-Routing-Switching/USG-update-for-dnsmasq-vulnerabilities/m-p/208...
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 09:57 AM
Thanks for bringing this up. We are aware and actively working on providing a firmware update to address these vulnerabilities very soon. I will post here as soon as the release is available.
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 12:34 PM
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 12:44 PM
@the_slain_man dnsmasq is used for DNS forwarding which is enabled by default. It can also be used for DHCP however, EdgeOS uses ISC dhcpd by default for DHCP. Regardless, it will be important to update to hotfix4 when it is released.
Re: dnsmasq vunlerabilities
[ Edited ]- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017
04:40 PM
- last edited on
10-04-2017
08:45 AM
by
UBNT-afomins
Release including update to come, but for those who want to install it in the mean time, here are the updated dnsmasq packages for MIPS platform (not MIPSEL, which is ER-X and ER-X-SFP only). These are appropraiate for all USG models, ERL, ERPro, ER-POE, ER-8-XG, all ERs except ER-X models.
https://dl.ubnt-ut.com/cmb/dnsmasq_2.78-1-ubnt1_all.deb
https://dl.ubnt-ut.com/cmb/dnsmasq-base_2.78-1-ubnt1_mips.deb
https://dl.ubnt-ut.com/cmb/dnsmasq-utils_2.78-1-ubnt1_mips.deb
Download those to ER and install them, like the following after SSH into the device.
sudo su curl -O https://dl.ubnt-ut.com/cmb/dnsmasq_2.78-1-ubnt1_all.deb curl -O https://dl.ubnt-ut.com/cmb/dnsmasq-base_2.78-1-ubnt1_mips.deb curl -O https://dl.ubnt-ut.com/cmb/dnsmasq-utils_2.78-1-ubnt1_mips.deb dpkg -i dnsmasq*
Choose the default "N" for any conflict prompts, and ignore any rc.d warnings.
If you try that, please report back here with results. It's running fine on multiple systems here internally, but would be good to hear from others.
*** UPDATE by UBNT-afomins ***
Here's update dnsmasq for ER-X, ER-X-SFP and EP-R6:
https://dl.ubnt.com/firmwares/edgemax/afomins/dnsmasq-2.78-e50/dnsmasq-base_9dev_mipsel.deb
https://dl.ubnt.com/firmwares/edgemax/afomins/dnsmasq-2.78-e50/dnsmasq-utils_9dev_mipsel.deb
https://dl.ubnt.com/firmwares/edgemax/afomins/dnsmasq-2.78-e50/dnsmasq_9dev_all.deb
New 1.9.7+hotfix.4 with those fixes will be release early next week.
Re: dnsmasq vunlerabilities
[ Edited ]- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 04:49 PM - edited 10-03-2017 04:50 PM
> If you try that, please report back here with results. It's running fine on multiple systems here internally, but would be good to hear from others
Installed successfully on an ER-L running v1.9.7+hotfix.3. Appears to be functioning properly.
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 05:23 PM
Re: dnsmasq vunlerabilities
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 07:53 PM
Installed successfully on ERLite 1.9.7+hotfix2.
Re: dnsmasq vunlerabilities
[ Edited ]- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
10-03-2017 08:02 PM - edited 10-03-2017 08:03 PM
Working fine so far with a ERPOE-5 with hotfix3. It's only been 2 hours but no instant problems.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Sticky This Topic
- Bookmark
- Subscribe
- Printer Friendly Page