OESA-2024-1905

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1905
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2024-1905.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2024-1905
Upstream
Published
2024-07-26T11:08:38Z
Modified
2025-09-03T06:19:39.593526Z
Summary
dnsmasq security update
Details

Dnsmasq provides network infrastructure for small networks: DNS, DHCP, router advertisement and network boot. It is designed to be lightweight and have a small footprint, suitable for resource constrained routers and firewalls. It has also been widely used for tethering on smartphones and portable hotspots, and to support virtual networking in virtualisation frameworks.

Security Fix(es):

dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.(CVE-2023-49441)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP1 / dnsmasq

Package

Name
dnsmasq
Purl
pkg:rpm/openEuler/dnsmasq&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.86-8.oe2203sp1

Ecosystem specific

{
    "x86_64": [
        "dnsmasq-2.86-8.oe2203sp1.x86_64.rpm",
        "dnsmasq-debuginfo-2.86-8.oe2203sp1.x86_64.rpm",
        "dnsmasq-debugsource-2.86-8.oe2203sp1.x86_64.rpm",
        "dnsmasq-help-2.86-8.oe2203sp1.x86_64.rpm"
    ],
    "src": [
        "dnsmasq-2.86-8.oe2203sp1.src.rpm"
    ],
    "aarch64": [
        "dnsmasq-2.86-8.oe2203sp1.aarch64.rpm",
        "dnsmasq-debuginfo-2.86-8.oe2203sp1.aarch64.rpm",
        "dnsmasq-debugsource-2.86-8.oe2203sp1.aarch64.rpm",
        "dnsmasq-help-2.86-8.oe2203sp1.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2024-1905.json"