Heap-based buffer overflow in Dnsmasq - CVE-2017-14491

 

Heap-based buffer overflow in Dnsmasq - CVE-2017-14491

Published: October 2, 2017 / Updated: March 2, 2021


Vulnerability identifier: #VU8660
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14491
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error in dnsmasq.c file when processing DNS replies. A remote unauthenticated attacker can send specially crafted DNS packets to the affected service, trigger heap-based buffer overflow by 2 bytes and crash the service or execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Dnsmasq
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Google Android
SUSE Linux
Ubuntu
Slackware Linux
Fedora
SCALANCE S615
SCALANCE M800
SCALANCE W1750D
dnsmasq (Alpine package)
dnsmasq (Red Hat package)
dnsmasq
Samsung Mobile Firmware
Edgeline EL300 Converged Edge System

How to mitigate CVE-2017-14491

Update to version 2.78.

dnsmasq (Alpine package) - addressed in versions 2.76-r1, 2.76-r2
Samsung Mobile Firmware - update to SMR-MAR-2021
Edgeline EL300 Converged Edge System - update to 1.50
dnsmasq (Red Hat package) - addressed in versions 2.45-2.el5_9.1, 2.45-2.el5_11.1
dnsmasq - addressed in versions 2.76-4.fc25, 2.76-5.fc26, 2.77-9.fc27

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins