Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 03:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.html - Issue Tracking, Mailing List, Third Party Advisory | |
References | () http://nvidia.custhelp.com/app/answers/detail/a_id/4561 - | |
References | () http://thekelleys.org.uk/dnsmasq/CHANGELOG - Release Notes, Vendor Advisory | |
References | () http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=897c113fda0886a28a986cc6ba17bb93bd6cb1c7 - | |
References | () http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txt - | |
References | () http://www.debian.org/security/2017/dsa-3989 - Third Party Advisory | |
References | () http://www.securityfocus.com/bid/101085 - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/101977 - | |
References | () http://www.securitytracker.com/id/1039474 - Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/USN-3430-1 - Third Party Advisory | |
References | () http://www.ubuntu.com/usn/USN-3430-2 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2017:2836 - Patch, Third Party Advisory | |
References | () https://access.redhat.com/security/vulnerabilities/3199382 - Issue Tracking, Third Party Advisory | |
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf - | |
References | () https://security.gentoo.org/glsa/201710-27 - | |
References | () https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html - Third Party Advisory | |
References | () https://source.android.com/security/bulletin/2017-10-01 - Third Party Advisory | |
References | () https://www.exploit-db.com/exploits/42946/ - Third Party Advisory, VDB Entry | |
References | () https://www.kb.cert.org/vuls/id/973527 - Third Party Advisory, US Government Resource | |
References | () https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.html - | |
References | () https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.html - | |
References | () https://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq - |
Information
Published : 2017-10-03 01:29
Updated : 2024-11-21 03:12
NVD link : CVE-2017-14496
Mitre link : CVE-2017-14496
CVE.ORG link : CVE-2017-14496
JSON object : View
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux_server
- enterprise_linux_workstation
canonical
- ubuntu_linux
novell
- leap
- android
thekelleys
- dnsmasq
debian
- debian_linux
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)