DNSMasq Critically Vulnerable to DNS Cache Poisoning Attacks

Date:

Share post:

Cybersecurity experts from security firm JSOF uncovered seven critical vulnerabilities in popular open-source Domain Name System (DNS) forwarding software DNSMasq, which is deployed in networking units to cache and forward Domain Identify Method requests. Dubbed as DNSpooq, the vulnerabilities include four Buffer Overflow Flaws (CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, and CVE-2020-25681) and three DNS Cache Poisoning vulnerabilities (CVE-2020-25686, CVE-2020-25684, and CVE-2020-25685).

Various popular brands like Cisco, Android, Aruba, Technicolor, Red-Hat, Siemens, Ubiquiti Networks, and Comcast use DNSMasq in their products and services.  JSOF’s researchers stated that the devices that are using DNSMasq could be affected or unaffected based on how they are using the software.

“One of the interesting things about these vulnerabilities is that each one of them, on its own, has limited impact. However, the vulnerabilities could be combined and chained in certain ways to build extremely effective multi-staged attacks. This is because exploiting some of the vulnerabilities makes it easier to exploit others,” JSOF said.

What’s the impact?

The Buffer Overflow vulnerabilities include high severity risks that could potentially lead to remote code execution when configured to DNSMasq. These vulnerabilities could pose critical risks when attackers combine these with the cache-poisoning vulnerabilities to launch more effective cyberattacks.

DNS Cache Poisoning flaws can potentially result in various kinds of frauds. Scammers could exploit these vulnerabilities to route unwitting victims from a legitimate browser to a malicious one. Fraudsters can manipulate the Internet traffic, including regular Internet browsing, emails, SSH, remote desktop, RDP video and voice calls, and software updates.

“For the Buffer Overflows and Remote Code execution, devices that don’t use the DNSSEC feature will be immune. DNSSEC is a security feature meant to prevent cache poisoning attacks and so we would not recommend turning it off, but rather updating to the newest version of DNSMasq,” JSOF added.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...

Model-Borne Consequence: Why OT Security and Data Security Just Became the Same Job

For thirty years we told you industrial cybersecurity was fundamentally different from IT cybersecurity. We were right. Then...

Truth, Transparency, and a Subpoena: Inside TikTok’s Security Crisis with Roland Cloutier

How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the...