Vulnerability Name:

CVE-2017-14495

Assigned:2017-10-02
Published:2017-10-02
Updated:2018-05-10
Summary:Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
CVSS v3 Severity:7.5 High (CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
7.0 High (Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
7.0 High (CCN Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (REDHAT CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
7.0 High (REDHAT Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (REDHAT CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-399
CWE-400
References:Source: SUSE
Type: VENDOR_ADVISORY
openSUSE-SU-2017:2633

Source: CONFIRM
Type: UNKNOWN
http://nvidia.custhelp.com/app/answers/detail/a_id/4561

Source: CONFIRM
Type: VENDOR_ADVISORY
http://thekelleys.org.uk/dnsmasq/CHANGELOG

Source: CONFIRM
Type: VENDOR_ADVISORY
http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=51eadb692a5123b9838e5a68ecace3ac579a3a45

Source: CONFIRM
Type: UNKNOWN
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txt

Source: DEBIAN
Type: VENDOR_ADVISORY
DSA-3989

Source: BID
Type: VENDOR_ADVISORY
101085

Source: BID
Type: UNKNOWN
101977

Source: SECTRACK
Type: VENDOR_ADVISORY
1039474

Source: UBUNTU
Type: VENDOR_ADVISORY
USN-3430-1

Source: UBUNTU
Type: VENDOR_ADVISORY
USN-3430-2

Source: REDHAT
Type: VENDOR_ADVISORY
RHSA-2017:2836

Source: CONFIRM
Type: VENDOR_ADVISORY
https://access.redhat.com/security/vulnerabilities/3199382

Source: CONFIRM
Type: UNKNOWN
https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf

Source: XF
Type: UNKNOWN
dnsmasq-cve201714495-dos(132935)

Source: GENTOO
Type: UNKNOWN
GLSA-201710-27

Source: MISC
Type: VENDOR_ADVISORY
https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html

Source: EXPLOIT-DB
Type: VENDOR_ADVISORY
42945

Source: CERT-VN
Type: VENDOR_ADVISORY
VU#973527

Source: MLIST
Type: VENDOR_ADVISORY
[dnsmasq-discuss] 20171002 IMPORTANT SECURITY INFORMATION.

Source: MLIST
Type: VENDOR_ADVISORY
[dnsmasq-discuss] 20171002 Announce: dnsmasq-2.78.

Source: CONFIRM
Type: UNKNOWN
https://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq

Vulnerable Configuration:Configuration 1:
  • cpe:/o:canonical:ubuntu_linux:14.04::~~lts~~~:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:novell:leap:42.2:*:*:*:*:*:*:*
  • OR cpe:/o:novell:leap:42.3:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:thekelleys:dnsmasq:2.77:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201714495
    V
    CVE-2017-14495
    2018-07-19
    oval:com.ubuntu.xenial:def:201714495000
    V
    CVE-2017-14495 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-10-02
    oval:com.ubuntu.trusty:def:201714495000
    V
    CVE-2017-14495 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-10-02
    oval:com.redhat.rhsa:def:20172836
    P
    RHSA-2017:2836: dnsmasq security update (Critical)
    2017-10-02
    BACK
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 17.04
    debian debian linux 7.0
    debian debian linux 7.1
    debian debian linux 9.0
    novell leap 42.2
    novell leap 42.3
    redhat enterprise linux desktop 7.0
    redhat enterprise linux server 7.0
    redhat enterprise linux workstation 7.0
    thekelleys dnsmasq 2.77