[LEDE-DEV] [PATCH v1] dnsmasq: backport dnssec security fix

2018-01-19 Thread Kevin Darbyshire-Bryant
CVE-2017-15107 An interesting problem has turned up in DNSSEC validation. It turns out that NSEC records expanded from wildcards are allowed, so a domain can include an NSEC record for *.example.org and an actual query reply could expand that to anything in example.org and still have it signed by

[LEDE-DEV] [PATCH v1] dnsmasq: backport dnssec security fix for 17.01

2018-01-19 Thread Kevin Darbyshire-Bryant
CVE-2017-15107 An interesting problem has turned up in DNSSEC validation. It turns out that NSEC records expanded from wildcards are allowed, so a domain can include an NSEC record for *.example.org and an actual query reply could expand that to anything in example.org and still have it signed by