Описание
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
An integer underflow flaw leading to a buffer over-read was found in dnsmasq in the DNS code. An attacker could send crafted DNS packets to dnsmasq which would cause it to crash.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux 6 | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux 7 | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | dnsmasq | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 11 (Ocata) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 12 (Pike) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | dnsmasq | Not affected | ||
| Red Hat OpenStack Platform 9 (Mitaka) | dnsmasq | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
In dnsmasq before 2.78, if the DNS packet size does not match the expe ...
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
Уязвимость функции memset() DNS-сервера Dnsmasq, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3