Memory corruption in Dnsmasq - CVE-2017-13704
Published: October 3, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to boundary error in when processing DNS queries longer than 512 bytes or EDNS0 packet size is different. A remote unauthenticated attacker can send a specially crafted DNS request to the affected service and trigger the application crash.
Successful exploitation of this vulnerability may allow an attacker to perform a denial of service (DoS) attack.
Affected software
SCALANCE W1750D
SCALANCE M800
SCALANCE S615
dnsmasq (Alpine package)
dnsmasq
Slackware Linux
Fedora
Edgeline EL300 Converged Edge System
How to mitigate CVE-2017-13704
Edgeline EL300 Converged Edge System - update to 1.50
dnsmasq - update to 2.77-7.fc27