From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp1 ([2001:41d0:8:6d80::]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by ms0.migadu.com with LMTPS id cCjuBWqscGDxGgAAgWs5BA (envelope-from ) for ; Fri, 09 Apr 2021 21:35:06 +0200 Received: from aspmx1.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp1 with LMTPS id uAx9O2mscGAFcwAAbx9fmQ (envelope-from ) for ; Fri, 09 Apr 2021 19:35:05 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 6F18515A9E for ; Fri, 9 Apr 2021 21:35:05 +0200 (CEST) Received: from localhost ([::1]:48634 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lUwuG-0001Gc-Jt for larch@yhetil.org; Fri, 09 Apr 2021 15:35:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:40030) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lUwtG-0000Zi-OX for bug-guix@gnu.org; Fri, 09 Apr 2021 15:34:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:39410) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1lUwtG-0001du-1w for bug-guix@gnu.org; Fri, 09 Apr 2021 15:34:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1lUwtF-0007Vi-W9 for bug-guix@gnu.org; Fri, 09 Apr 2021 15:34:02 -0400 X-Loop: help-debbugs@gnu.org Subject: bug#47674: dnsmasq is vulnerable to CVE-2021-3448 Resent-From: Leo Famulari Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Fri, 09 Apr 2021 19:34:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 47674 X-GNU-PR-Package: guix X-GNU-PR-Keywords: security To: =?UTF-8?Q?Nicol=C3=B2?= Balzarotti Received: via spool by 47674-submit@debbugs.gnu.org id=B47674.161799681328822 (code B ref 47674); Fri, 09 Apr 2021 19:34:01 +0000 Received: (at 47674) by debbugs.gnu.org; 9 Apr 2021 19:33:33 +0000 Received: from localhost ([127.0.0.1]:50954 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lUwsm-0007Un-Tn for submit@debbugs.gnu.org; Fri, 09 Apr 2021 15:33:33 -0400 Received: from out5-smtp.messagingengine.com ([66.111.4.29]:44785) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lUwsl-0007UY-1E for 47674@debbugs.gnu.org; Fri, 09 Apr 2021 15:33:31 -0400 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 8144E5C010B; Fri, 9 Apr 2021 15:33:25 -0400 (EDT) Received: from mailfrontend1 ([10.202.2.162]) by compute3.internal (MEProxy); Fri, 09 Apr 2021 15:33:25 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=date:from:to:cc:subject:message-id:references:mime-version :content-type:in-reply-to; s=mesmtp; bh=ha7bEO3W5mQ2cS4HlTvJx2/K BrFqzzMDkY1vkT4a03g=; b=x7stZ5U69WAPAN+QmJGCRO7EicdP5i2xni5Gdy0X A0AWIqa2/7VR1YIfMEyzCFZScJE+ObIbYc1UxEGuDqcgotCxpInqhfsUF4+2aekE /P8qL/4sEK7ZQOr0VfutNzajDd9g3tT3GaN6ZGzLwow4fkBcJGYNlD6Rvu16KVaU QGI= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=ha7bEO 3W5mQ2cS4HlTvJx2/KBrFqzzMDkY1vkT4a03g=; b=S4Ob5/r+LeSDH7NqT0fbEQ MNlcmVvkhpyHeCTJrktkRG79rx7+BuJbeV8aBogrPdkY2JbBpiwMBklN576wasGY xHrb6U4JLK8Ho510cdGJawOwAcRktBmdhz5OmrY/nkjyaJbI7FbZXg+3uk8JkHKG Okoqmg2CVbK6U80X1KNIuZKFOdYYJniuSmXUD0AW6yCEOm8P5p8aF0KAn2SbHhP8 jXAbuOVtnM9kcqYuIYyYiPw40AkN80O9zsymvhdfaWEu1cpW/89CWQoz7LW+VR4l fXh+6nYLAQb+PX/1HlnAh2Mv/osKADwMudSpJJ95OjXzwxIJe5BDz2Jz/g+TeKYQ == X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrudekuddgudegvdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh necuuegrihhlohhuthemuceftddtnecunecujfgurhepfffhvffukfhfgggtuggjsehgtd erredttddunecuhfhrohhmpefnvghoucfhrghmuhhlrghrihcuoehlvghosehfrghmuhhl rghrihdrnhgrmhgvqeenucggtffrrghtthgvrhhnpeduhfffveehtdfgjeevleefueekhf dtvdffteegueeigfevvdekfeeijeffgfffleenucfkphepuddttddruddurdduieelrddu udeknecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomheplh gvohesfhgrmhhulhgrrhhirdhnrghmvg X-ME-Proxy: Received: from localhost (pool-100-11-169-118.phlapa.fios.verizon.net [100.11.169.118]) by mail.messagingengine.com (Postfix) with ESMTPA id 36592240054; Fri, 9 Apr 2021 15:33:25 -0400 (EDT) Date: Fri, 9 Apr 2021 15:33:22 -0400 From: Leo Famulari Message-ID: References: <87pmz3mr2k.fsf@guixSD.i-did-not-set--mail-host-address--so-tickle-me> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="z4P2ohRx+psNzaCQ" Content-Disposition: inline In-Reply-To: <87pmz3mr2k.fsf@guixSD.i-did-not-set--mail-host-address--so-tickle-me> X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-guix@gnu.org List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: 47674@debbugs.gnu.org Errors-To: bug-guix-bounces+larch=yhetil.org@gnu.org Sender: "bug-Guix" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1617996905; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:resent-cc:resent-from:resent-sender: resent-message-id:in-reply-to:in-reply-to:references:references: list-id:list-help:list-unsubscribe:list-subscribe:list-post: dkim-signature; bh=ha7bEO3W5mQ2cS4HlTvJx2/KBrFqzzMDkY1vkT4a03g=; b=QfzMXBBYig47gcvu6yzNIuszdhBVGMsHSiWOljyJTKQFIiTwXAZ3KzCBWurAGDcsVogSzg slTFkCyCZXahEccWxTKeYUmNKOz1kb3cFqEXW8qeGX0Uv9AHplxlxxiXdQbuotkttFm04P H0aI/zY4Cuhqm3Rr1PyMGwPDINhH4yBnIU3oQdpTkuaU+PkYn1+GqQ8Pz733OqGDD06QmF Ex3TQ8Tq5DlfzYAexC4uLXv2JdQpfLBBgd1exgUPyPc5M99gVKh+znDPa1CvmOhXogXLxA 3NkICpGvMufa5Iuyo7ImUnyl/NdFtNPoHpuP5Ag8KtJN2nVN+s357zjgwbzD9w== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1617996905; a=rsa-sha256; cv=none; b=MKADvI2qWHGu8pF+p29cQXLErzvnW2tLzMVUW79pF3/lhlo0a1w5Cqp0R5mnXeZt68IoZ3 pf6nJb9DMC8YyAwwJ5w+lqk21tu9OO0Vl0PGiDTshPARuT238WzzDY80lYui//KjEDl5Hc KAQ3Oop8qxyiYjQUMBlZpQKbHvS+T2rpWuGmaEID5mUVLFIGMUUHZg8Gkk0DRMggyxgC6I TCyR0fpdm4D63eFIh/1rDBSjR4Wr0iJZpZwOQY1HA/ZJ8SiLPIewGV/zVBrDWjDGBClIn6 ICYOQmbPE8j9IM9Ma+snKg+3NS+irHaFG4v4n2Bp5LdyUOUU6ZIRgwLMyVbpLA== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=famulari.name header.s=mesmtp header.b=x7stZ5U6; dkim=fail ("headers rsa verify failed") header.d=messagingengine.com header.s=fm2 header.b="S4Ob5/r+"; spf=pass (aspmx1.migadu.com: domain of bug-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=bug-guix-bounces@gnu.org X-Migadu-Spam-Score: -3.54 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=famulari.name header.s=mesmtp header.b=x7stZ5U6; dkim=fail ("headers rsa verify failed") header.d=messagingengine.com header.s=fm2 header.b="S4Ob5/r+"; dmarc=none; spf=pass (aspmx1.migadu.com: domain of bug-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=bug-guix-bounces@gnu.org X-Migadu-Queue-Id: 6F18515A9E X-Spam-Score: -3.54 X-Migadu-Scanner: scn0.migadu.com X-TUID: bhckKjKmGRGV --z4P2ohRx+psNzaCQ Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Apr 09, 2021 at 05:10:43PM +0200, Nicol=F2 Balzarotti wrote: > CVE-2021-3448 >=20 > A flaw was found in dnsmasq in versions before 2.85. When configured to > use a specific server for a given network interface, dnsmasq uses a > fixed port while forwarding queries. An attacker on the network, able to > find the outgoing port used by dnsmasq, only needs to guess the random > transmission ID to forge a reply and get it accepted by dnsmasq. This > flaw makes a DNS Cache Poisoning attack much easier. The highest threat > from this vulnerability is to data integrity. >=20 > guix ships dnsmasq@2.84. guix refresh shows version 2.85 is available, > and there are 43 dependent packages so this can go directly to master. >=20 > All dependent packages (refresh -l) build fine except for > python2-libvirt@7.2.0, which is failing also on master > (libvirt-python requires Python >=3D 3.5 to build). Since it's a python2 > package and no other packages depends on it, can we just drop it? Yes, sounds good. --z4P2ohRx+psNzaCQ Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAmBwrAIACgkQJkb6MLrK fwhojxAAo4Fh1COO5Q0PhKkgXu3xELiU1524x6yweg5Rqseuob6V7HrpuljmcsfO XFMPq2wMVghq6w6FcQDWxPblMkj3hRBquLnB1QZS0A/60RusX2gXQtg/DF+fkpIH IVLndXxS3npMp3Lo/06xls8WYCSVYCTP6CH5gS11wqaLK18a7nV1nxAsreHODUzs nLrLaArKcTouxe4rOsZWvD12dlePS45qBgKvMuwU/5W+jmHv60i8ExKUREs3LGux wAskCd0FZVtdIQpnD/e/NAboSgscqELnhehI0rMcGNrGIGQl+UIIGQ37iRL9e25f kDb2QC3x+R0oayQow0/x35dUNVSuKz9fIosrhrQvnWkeEHUVFteAZC1V7f7XJloo FnbC6rGb9Ch7+td1YHXdl7XX0xBNwo4SFdvbwAKQK4kjjxTiqNe5BS4BoaQGtxE+ 5X/LZMkI/ob56pyfVdmpRTd9G8VwjoccpESasmJx9xDWetfv1JSi9a5jZ9ulGu2l LBkVmhyVK4v3+Cu4AjWSTG0vDozH/4GgIZx5H9FH0QgEYqqktRx/d6WkFLyuk4Is CAbrnToJVek6q3y163XMivF9cSsxAGtBN+NnKshtvOoKL+qXWRe2JZ96LoayIGNd rdSTcrn7AiF0uUuTyTfz+JoWqFS+YWLdrkrpIX1Jz9lH8bzzbXA= =Oiqy -----END PGP SIGNATURE----- --z4P2ohRx+psNzaCQ--