Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-13704

Опубликовано: 03 окт. 2017
Источник: debian

Описание

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.78-1package
dnsmasqnot-affectedstretchpackage
dnsmasqnot-affectedjessiepackage
dnsmasqnot-affectedwheezypackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1495510

  • http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2017q3/011729.html

  • http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=63437ffbb58837b214b4b92cb1c54bc5f3279928

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

CVSS3: 7.5
redhat
больше 8 лет назад

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

CVSS3: 7.5
nvd
больше 8 лет назад

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

CVSS3: 7.5
github
больше 3 лет назад

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

CVSS3: 7.5
fstec
больше 8 лет назад

Уязвимость функции memset() DNS-сервера Dnsmasq, позволяющая нарушителю вызвать отказ в обслуживании