A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Dnsmasq | Thekelleys | * | 2.78 (including) |
| Dnsmasq | Ubuntu | artful | * |
| Dnsmasq | Ubuntu | esm-infra/xenial | * |
| Dnsmasq | Ubuntu | upstream | * |
| Dnsmasq | Ubuntu | xenial | * |