PT-2017-13488 · Simon Kelley+5 · Dnsmasq+5
Felix Wilhelm
+4
·
Publicado
2017-10-02
·
Atualizado
2024-06-15
·
CVE-2017-14495
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dnsmasq versions prior to 2.78
Description
The issue is related to a memory leak that can be triggered when specific options such as
--add-mac, --add-cpe-id, or --add-subnet are used. This allows remote attackers to cause a denial of service by consuming memory through vectors involving DNS response creation.Recommendations
For dnsmasq versions prior to 2.78, update to version 2.78 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the
--add-mac, --add-cpe-id, and --add-subnet options until the update is applied.Exploit
Correção
DoS
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Dnsmasq