Описание
Security update for dnsmasq
This update for dnsmasq fixes the following security issues:
- CVE-2017-14491: 2 byte heap based overflow. [bsc#1060354]
- CVE-2017-14492: heap based overflow. [bsc#1060355]
- CVE-2017-14493: stack based overflow. [bsc#1060360]
- CVE-2017-14494: DHCP - info leak. [bsc#1060361]
- CVE-2017-14495: DNS - OOM DoS. [bsc#1060362]
- CVE-2017-14496: DNS - DoS Integer underflow. [bsc#1060364]
Список пакетов
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
Ссылки
- Link for SUSE-SU-2017:2618-1
- E-Mail link for SUSE-SU-2017:2618-1
- SUSE Security Ratings
- SUSE Bug 1060354
- SUSE Bug 1060355
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
- SUSE CVE CVE-2017-14491 page
- SUSE CVE CVE-2017-14492 page
- SUSE CVE CVE-2017-14493 page
- SUSE CVE CVE-2017-14494 page
- SUSE CVE CVE-2017-14495 page
- SUSE CVE CVE-2017-14496 page
Описание
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Затронутые продукты
Ссылки
- CVE-2017-14491
- SUSE Bug 1060354
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
- SUSE Bug 1063832
- SUSE Bug 1143944
Описание
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.
Затронутые продукты
Ссылки
- CVE-2017-14492
- SUSE Bug 1060355
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
- SUSE Bug 1063832
Описание
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
Затронутые продукты
Ссылки
- CVE-2017-14493
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
- SUSE Bug 1063832
Описание
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
Затронутые продукты
Ссылки
- CVE-2017-14494
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
Описание
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
Затронутые продукты
Ссылки
- CVE-2017-14495
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
Описание
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
Затронутые продукты
Ссылки
- CVE-2017-14496
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364