ISOMAN

CVE

CVE-2017-13704

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://thekelleys.org.uk/dnsmasq/CHANGELOG
  2. http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=63437ffbb58837b214b4b92cb1c54bc5f3279928
  3. http://www.securityfocus.com/bid/101085
  4. http://www.securityfocus.com/bid/101977
  5. http://www.securitytracker.com/id/1039474
  6. https://access.redhat.com/security/vulnerabilities/3199382
  7. https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf
  8. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TK6DWC53WSU6633EVZL7H4PCWBYHMHK/
  9. https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html
  10. https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.html
  11. https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.html
  12. https://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq
  13. http://thekelleys.org.uk/dnsmasq/CHANGELOG
  14. http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=63437ffbb58837b214b4b92cb1c54bc5f3279928
  15. http://www.securityfocus.com/bid/101085
  16. http://www.securityfocus.com/bid/101977
  17. http://www.securitytracker.com/id/1039474
  18. https://access.redhat.com/security/vulnerabilities/3199382
  19. https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf
  20. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TK6DWC53WSU6633EVZL7H4PCWBYHMHK/