Vulnerability Name:

CVE-2017-14491

Assigned:2017-10-02
Published:2017-10-02
Updated:2018-05-10
Summary:Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
CVSS v3 Severity:9.8 Critical (CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
9.1 Critical (Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
9.1 Critical (CCN Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (REDHAT CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
9.1 Critical (REDHAT Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (REDHAT CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-119
CWE-122
References:Source: SUSE
Type: VENDOR_ADVISORY
openSUSE-SU-2017:2633

Source: CONFIRM
Type: UNKNOWN
http://nvidia.custhelp.com/app/answers/detail/a_id/4561

Source: CONFIRM
Type: VENDOR_ADVISORY
http://thekelleys.org.uk/dnsmasq/CHANGELOG

Source: CONFIRM
Type: VENDOR_ADVISORY
http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=0549c73b7ea6b22a3c49beb4d432f185a81efcbc

Source: CONFIRM
Type: UNKNOWN
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txt

Source: DEBIAN
Type: VENDOR_ADVISORY
DSA-3989

Source: BID
Type: VENDOR_ADVISORY
101085

Source: BID
Type: UNKNOWN
101977

Source: SECTRACK
Type: VENDOR_ADVISORY
1039474

Source: UBUNTU
Type: VENDOR_ADVISORY
USN-3430-1

Source: UBUNTU
Type: VENDOR_ADVISORY
USN-3430-2

Source: REDHAT
Type: VENDOR_ADVISORY
RHSA-2017:2836

Source: REDHAT
Type: VENDOR_ADVISORY
RHSA-2017:2837

Source: REDHAT
Type: VENDOR_ADVISORY
RHSA-2017:2838

Source: REDHAT
Type: VENDOR_ADVISORY
RHSA-2017:2839

Source: REDHAT
Type: VENDOR_ADVISORY
RHSA-2017:2840

Source: REDHAT
Type: VENDOR_ADVISORY
RHSA-2017:2841

Source: CONFIRM
Type: VENDOR_ADVISORY
https://access.redhat.com/security/vulnerabilities/3199382

Source: CONFIRM
Type: UNKNOWN
https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf

Source: XF
Type: UNKNOWN
dnsmasq-cve201714491-bo(132931)

Source: GENTOO
Type: UNKNOWN
GLSA-201710-27

Source: MISC
Type: VENDOR_ADVISORY
https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html

Source: EXPLOIT-DB
Type: VENDOR_ADVISORY
42941

Source: CERT-VN
Type: VENDOR_ADVISORY
VU#973527

Source: MLIST
Type: VENDOR_ADVISORY
[dnsmasq-discuss] 20171002 IMPORTANT SECURITY INFORMATION.

Source: MLIST
Type: VENDOR_ADVISORY
[dnsmasq-discuss] 20171002 Announce: dnsmasq-2.78.

Source: CONFIRM
Type: UNKNOWN
https://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq

Vulnerable Configuration:Configuration 1:
  • cpe:/o:canonical:ubuntu_linux:12.04::~~lts~~~:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.04::~~lts~~~:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:novell:leap:42.2:*:*:*:*:*:*:*
  • OR cpe:/o:novell:leap:42.3:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:thekelleys:dnsmasq:2.77:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201714491
    V
    CVE-2017-14491
    2018-07-19
    oval:com.ubuntu.xenial:def:201714491000
    V
    CVE-2017-14491 on Ubuntu 16.04 LTS (xenial) - high.
    2017-10-03
    oval:com.ubuntu.trusty:def:201714491000
    V
    CVE-2017-14491 on Ubuntu 14.04 LTS (trusty) - high.
    2017-10-03
    oval:com.redhat.rhsa:def:20172836
    P
    RHSA-2017:2836: dnsmasq security update (Critical)
    2017-10-02
    oval:com.redhat.rhsa:def:20172838
    P
    RHSA-2017:2838: dnsmasq security update (Critical)
    2017-10-02
    BACK
    canonical ubuntu linux 12.04
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 17.04
    debian debian linux 7.0
    debian debian linux 7.1
    debian debian linux 9.0
    novell leap 42.2
    novell leap 42.3
    redhat enterprise linux desktop 6.0
    redhat enterprise linux desktop 7.0
    redhat enterprise linux server 6.0
    redhat enterprise linux server 7.0
    redhat enterprise linux workstation 6.0
    redhat enterprise linux workstation 7.0
    thekelleys dnsmasq 2.77