Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers.
References
Configurations
No configuration.
History
21 Nov 2024, 09:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/mullvad/mullvadvpn-app/blob/main/CHANGELOG.md - | |
References | () https://github.com/mullvad/mullvadvpn-app/commit/0c39306a40f426853d617e20d596942e41091f13 - | |
References | () https://github.com/mullvad/mullvadvpn-app/tags - | |
References | () https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android - | |
References | () https://news.ycombinator.com/item?id=40247604 - |
01 Aug 2024, 13:52
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-923 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
Summary |
|
03 May 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-03 15:15
Updated : 2024-11-21 09:18
NVD link : CVE-2024-34446
Mitre link : CVE-2024-34446
CVE.ORG link : CVE-2024-34446
JSON object : View
Products Affected
No product.
CWE
CWE-923
Improper Restriction of Communication Channel to Intended Endpoints