Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14496

Опубликовано: 03 окт. 2017
Источник: debian

Описание

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.78-1package
dnsmasqfixed2.76-5+deb9u1stretchpackage
dnsmasqnot-affectedjessiepackage
dnsmasqnot-affectedwheezypackage

Примечания

  • https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html

  • https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=897c113fda0886a28a986cc6ba17bb93bd6cb1c7

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

CVSS3: 7.5
redhat
почти 9 лет назад

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

CVSS3: 7.5
nvd
почти 9 лет назад

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

CVSS3: 7.5
github
около 4 лет назад

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

CVSS3: 7.5
fstec
почти 9 лет назад

Уязвимость функции add_pseudoheader DNS-сервера Dnsmasq, позволяющая нарушителю вызвать отказ в обслуживании