Resource exhaustion - CVE-2019-14834
Published: January 7, 2020 / Updated: July 27, 2020
Vulnerability identifier: #VU31907
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14834
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
Affected software
Amazon Linux AMI
F5OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Ubuntu
Opensuse
Fedora
dnsmasq (Red Hat package)
dnsmasq (Alpine package)
dnsmasq (Ubuntu package)
dnsmasq-utils (Ubuntu package)
dnsmasq-base (Ubuntu package)
dnsmasq
F5OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Ubuntu
Opensuse
Fedora
dnsmasq (Red Hat package)
dnsmasq (Alpine package)
dnsmasq (Ubuntu package)
dnsmasq-utils (Ubuntu package)
dnsmasq-base (Ubuntu package)
dnsmasq
How to mitigate CVE-2019-14834
Install update from vendor's website.
dnsmasq (Red Hat package) - addressed in versions 2.76-16.el7, 2.79-11.el8
dnsmasq (Alpine package) - update to 2.79-r4
dnsmasq (Ubuntu package) - addressed in versions 2.68-1ubuntu0.2+esm3, 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq-utils (Ubuntu package) - addressed in versions 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq-base (Ubuntu package) - addressed in versions 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq - update to 2.76-16.16
dnsmasq - update to 2.80-15.fc31
dnsmasq (Alpine package) - update to 2.79-r4
dnsmasq (Ubuntu package) - addressed in versions 2.68-1ubuntu0.2+esm3, 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq-utils (Ubuntu package) - addressed in versions 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq-base (Ubuntu package) - addressed in versions 2.75-1ubuntu0.16.04.7, 2.75-1ubuntu0.16.04.8, 2.79-1ubuntu0.2, 2.79-1ubuntu0.3, 2.80-1.1ubuntu1.2, 2.80-1.1ubuntu1.3, 2.82-1ubuntu1.1, 2.82-1ubuntu1.2
dnsmasq - update to 2.76-16.16
dnsmasq - update to 2.80-15.fc31
External References
Related Security Bulletins
- OpenSUSE Linux update for dnsmasq
- Resource exhaustion in dnsmasq (Alpine package)
- Red Hat Enterprise Linux 7 update for dnsmasq
- Ubuntu update for dnsmasq
- Ubuntu update for dnsmasq
- Red Hat Enterprise Linux 8 update for dnsmasq
- Amazon Linux AMI update for dnsmasq
- Fedora 31 update for dnsmasq
- Denial of service in F5OS dnsmasq
- Ubuntu update for dnsmasq