HIGH 7.5 Microsoft
CVE-2023-28450
An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.
Microsoft Security Update 2023-Mar: An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.
Affected Products
- cm1 dnsmasq 2.85-2 on CBL Mariner 1.0
- cbl2 dnsmasq 2.89-2 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28450
- https://nvd.nist.gov/vuln/detail/CVE-2023-28450
This high severity vulnerability with a CVSS score of 7.5 was published on 2023-03-14 via Microsoft. Affected: cm1 dnsmasq 2.85-2 on CBL Mariner 1.0, cbl2 dnsmasq 2.89-2 on CBL Mariner 2.0.
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.