Back to Database
Status published
Critical
CVE-2017-14491
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers...
Vulnerability Description
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-14491
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securitytracker.com/id/1039474
- https://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq
- http://www.debian.org/security/2017/dsa-3989
- https://access.redhat.com/security/vulnerabilities/3199382
- http://www.securityfocus.com/bid/101085
- http://www.ubuntu.com/usn/USN-3430-1
- http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=0549c73b7ea6b22a3c49beb4d432f185a81efcbc
- http://www.securityfocus.com/bid/101977
- https://access.redhat.com/errata/RHSA-2017:2838
- https://www.kb.cert.org/vuls/id/973527
- https://security.gentoo.org/glsa/201710-27
- https://access.redhat.com/errata/RHSA-2017:2840
- http://www.ubuntu.com/usn/USN-3430-2
- https://access.redhat.com/errata/RHSA-2017:2839
- https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.html
- https://access.redhat.com/errata/RHSA-2017:2836
- http://nvidia.custhelp.com/app/answers/detail/a_id/4561
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txt
- https://access.redhat.com/errata/RHSA-2017:2837
- https://www.exploit-db.com/exploits/42941/
- http://thekelleys.org.uk/dnsmasq/CHANGELOG
- https://access.redhat.com/errata/RHSA-2017:2841
- http://nvidia.custhelp.com/app/answers/detail/a_id/4560
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.html
- https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html
- https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MMPCJOYPPL4B5RBY4U425PWG7EETDTD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXRZ2W6TV6NLUJC5NOFBSG6PZSMDTYPV/
- http://www.ubuntu.com/usn/USN-3430-3
- http://packetstormsecurity.com/files/144480/Dnsmasq-2-Byte-Heap-Based-Overflow.html
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00005.html
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-449/
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171103-01-dnsmasq-en
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-449
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/527KNN34RN2SB6MBJG7CKSEBWYE3TJEB/
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00004.html
- https://www.debian.org/security/2017/dsa-3989
- https://www.arista.com/en/support/advisories-notices/security-advisories/3577-security-advisory-30
More from thekelleys
View All →CVE-2021-45957
Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called...
Critical
9.8
CVE-2021-45956
Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called...
Unknown
0
CVE-2021-45955
Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called...
Critical
9.8
CVE-2021-45954
Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called...
Critical
9.8
CVE-2021-45953
Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called...
Critical
9.8
Affected Vendor
thekelleys
View all reports →Affected Software
dnsmasq, enterprise linux desktop, enterprise linux server, enterprise linux workstation, ubuntu linux, debian linux, leap, linux enterprise debuginfo, linux enterprise point of sale, linux enterprise server, linux for tegra, geforce experience, honor v9 play firmware, eos, ruggedcom rm1224 firmware, scalance m-800 firmware, scalance s615 firmware, scalance w1750d firmware, arubaos, router manager, diskstation manager
Vulnerable Versions:
0, 6.0, 7.0, 12.04, 14.04, 16.04, 17.04, 7.1, 8.0, 9.0, 42.2, 42.3, 11, 12, 3.0, 4.16, 4.17, 4.18, 6.3.1, 6.4.4.0, 6.5.0.0, 6.5.3.0, 6.5.4.0, 8.1.0.0, 1.1, 5.2, 6.1
Timeline
Official Publish:
October 2nd, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.