CVE-2006-2017Classic Buffer Overflow in Dnsmasq

Severity
5.0MEDIUMNVD
EPSS
1.3%
top 20.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateMay 1

Description

Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianthekelleys/dnsmasq< 2.30-1+3
NVDdnsmasq/dnsmasq2.29

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c65g-3xxp-xxjh: Dnsmasq 22022-05-01
OSV
CVE-2006-2017: Dnsmasq 22006-04-25
CVEList
CVE-2006-2017: Dnsmasq 22006-04-25

💥Exploits & PoCs

2
Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow2017-12-13
Exploit-DB
OpenSSL 1.1.0 - Remote Client Denial of Service2017-01-26

📋Vendor Advisories

3
Red Hat
glibc: Buffer overflow triggerable via LD_LIBRARY_PATH2017-12-11
Red Hat
openssl: Malformed X.509 IPAdressFamily could cause OOB read2017-08-28
Debian
CVE-2006-2017: dnsmasq - Dnsmasq 2.29 allows remote attackers to cause a denial of service (application c...2006

💬Community

1
HackerOne
Linux kernel: CVE-2017-6074: DCCP double-free vulnerability2019-08-27
CVE-2006-2017 — Classic Buffer Overflow in Dnsmasq | cvebase