cbcvebase.
CVE-2017-14491
published 2017-10-04

CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos<= 4.15
aristaeos>= 4.16 < 4.16.13m4.16.13m
aristaeos>= 4.17 < 4.17.8m4.17.8m
aristaeos4.18 – 4.18.4.2f
arubanetworksarubaos>= 6.3.1 < 6.3.1.256.3.1.25
arubanetworksarubaos>= 6.4.4.0 < 6.4.4.166.4.4.16
arubanetworksarubaos>= 6.5.0.0 < 6.5.1.96.5.1.9
arubanetworksarubaos>= 6.5.3.0 < 6.5.3.36.5.3.3
arubanetworksarubaos>= 6.5.4.0 < 6.5.4.26.5.4.2
arubanetworksarubaos>= 8.1.0.0 < 8.1.0.48.1.0.4
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiandnsmasq< dnsmasq 2.76-1 (bookworm)dnsmasq 2.76-1 (bookworm)
debiandnsmasq< dnsmasq 2.78-1 (bookworm)dnsmasq 2.78-1 (bookworm)
googleandroid
huaweihonor_v9_play_firmware< jimmy-al00ac00b135jimmy-al00ac00b135
nvidiageforce_experience>= 3.0 < 3.10.0.553.10.0.55
nvidialinux_for_tegra< r21.6r21.6
nvidialinux_for_tegra< r24.2.2r24.2.2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL