Описание
Security update for dnsmasq
This update for dnsmasq fixes the following security issues:
- CVE-2017-14491: 2 byte heap based overflow. [bsc#1060354]
- CVE-2017-14492: heap based overflow. [bsc#1060355]
- CVE-2017-14493: stack based overflow. [bsc#1060360]
- CVE-2017-14494: DHCP - info leak. [bsc#1060361]
- CVE-2017-14495: DNS - OOM DoS. [bsc#1060362]
- CVE-2017-14496: DNS - DoS Integer underflow. [bsc#1060364]
This update was imported from the SUSE:SLE-12-SP1:Update update project.
Список пакетов
openSUSE Leap 42.2
openSUSE Leap 42.3
Ссылки
- E-Mail link for openSUSE-SU-2017:2633-1
- SUSE Security Ratings
Описание
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Затронутые продукты
Ссылки
- CVE-2017-14491
- SUSE Bug 1060354
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
- SUSE Bug 1063832
- SUSE Bug 1143944
Описание
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.
Затронутые продукты
Ссылки
- CVE-2017-14492
- SUSE Bug 1060355
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
- SUSE Bug 1063832
Описание
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
Затронутые продукты
Ссылки
- CVE-2017-14493
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
- SUSE Bug 1063832
Описание
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
Затронутые продукты
Ссылки
- CVE-2017-14494
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
Описание
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
Затронутые продукты
Ссылки
- CVE-2017-14495
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364
Описание
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
Затронутые продукты
Ссылки
- CVE-2017-14496
- SUSE Bug 1060360
- SUSE Bug 1060361
- SUSE Bug 1060362
- SUSE Bug 1060364