CVE-2017-14491
published 2017-10-04CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS…
PriorityP182critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
84.92%
99.7th percentile
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | eos | <= 4.15 | — |
| arista | eos | >= 4.16 < 4.16.13m | 4.16.13m |
| arista | eos | >= 4.17 < 4.17.8m | 4.17.8m |
| arista | eos | 4.18 – 4.18.4.2f | — |
| arubanetworks | arubaos | >= 6.3.1 < 6.3.1.25 | 6.3.1.25 |
| arubanetworks | arubaos | >= 6.4.4.0 < 6.4.4.16 | 6.4.4.16 |
| arubanetworks | arubaos | >= 6.5.0.0 < 6.5.1.9 | 6.5.1.9 |
| arubanetworks | arubaos | >= 6.5.3.0 < 6.5.3.3 | 6.5.3.3 |
| arubanetworks | arubaos | >= 6.5.4.0 < 6.5.4.2 | 6.5.4.2 |
| arubanetworks | arubaos | >= 8.1.0.0 < 8.1.0.4 | 8.1.0.4 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | dnsmasq | < dnsmasq 2.76-1 (bookworm) | dnsmasq 2.76-1 (bookworm) |
| debian | dnsmasq | < dnsmasq 2.78-1 (bookworm) | dnsmasq 2.78-1 (bookworm) |
| android | — | — | |
| huawei | honor_v9_play_firmware | < jimmy-al00ac00b135 | jimmy-al00ac00b135 |
| nvidia | geforce_experience | >= 3.0 < 3.10.0.55 | 3.10.0.55 |
| nvidia | linux_for_tegra | < r21.6 | r21.6 |
| nvidia | linux_for_tegra | < r24.2.2 | r24.2.2 |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
DNS PTR response flags=0x85a0, answers=0x52, crafted label chain with 0x3e+'Z'*62 repeated segments and compressed pointer 0xc4 0x40
- ·Only dnsmasq versions before 2.78 are vulnerable; upgrade to 2.78 or later to remediate. ↗
- ·Red Hat OpenStack Platform ships dnsmasq-utils RPM which does not contain the affected code paths and is not directly vulnerable, but the underlying RHEL dnsmasq package must still be patched. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2017-14491: Android Security Bulletin 2021-03-01
CVE: CVE-2017-14491
Severity: HIGH
Type: RCE
Affected AOSP versions: 8
vendor_android·2021-03-01·CVSS 9.8
CVE-2017-14491 [CRITICAL] CVE-2017-14491: Android Security Bulletin 2021-03-01
CVE: CVE-2017-14491
Severity: HIGH
Type: RCE
Affected AOSP versions: 8
Android Security Bulletin 2021-03-01
CVE: CVE-2017-14491
Severity: HIGH
Type: RCE
Affected AOSP versions: 8.1, 9, 10, 11
References: A-158221622
Red Hat
dnsmasq: Improper bounds checking leads to a buffer overread
vendor_redhat·2019-08-09·CVSS 9.8
CVE-2019-14513 [CRITICAL] CWE-119 dnsmasq: Improper bounds checking leads to a buffer overread
dnsmasq: Improper bounds checking leads to a buffer overread
Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
Statement: This issue does not affect the versions of dnsmasq as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8.
In Red Hat OpenStack Platform, which currently supports Red Hat Enterprise Linux 7.7, the dnsmasq package is pulled directly from the rhel-7-server-rpms channel. Red Hat OpenStack Platform is therefore unaffected, but please ensure that the underlying Red Hat Enterprise Linux dnsmasq package is current.
Package: dnsmasq (Red Hat Enterprise Linux 5) - Not affected
Package: dns
Debian
CVE-2019-14513: dnsmasq - Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DN...
vendor_debian·2019·CVSS 9.8
CVE-2019-14513 [CRITICAL] CVE-2019-14513: dnsmasq - Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DN...
Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
Scope: local
bookworm: resolved (fixed in 2.76-1)
bullseye: resolved (fixed in 2.76-1)
forky: resolved (fixed in 2.76-1)
sid: resolved (fixed in 2.76-1)
trixie: resolved (fixed in 2.76-1)
CISA ICS
Siemens SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224 (Update C)
cisa_ics·2018-05-10·CVSS 7.5
[HIGH] Siemens SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224 (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224 (Update C)
Last RevisedOctober 13, 2020
Alert CodeICSA-17-332-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Siemens
--------- Begin Update C Part 1 of 3 --------
- Equipment: SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224
--------- End Update C Part 1 of 3 --------
- Vulnerabilities: Resource Exhaustion, Improper Restriction of Operations within the Bounds of a Memory Buffer
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the up
Ubuntu
Dnsmasq regression
vendor_ubuntu·2018-01-04·CVSS 9.8
[CRITICAL] Dnsmasq regression
Title: Dnsmasq regression
Summary: USN-3430-2 introduced regression in Dnsmasq.
USN-3430-2 fixed several vulnerabilities. The update introduced a new
regression that breaks DNS resolution. This update addresses the problem.
We apologize for the inconvenience.
Original advisory details:
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2017-10-03·CVSS 9.8
CVE-2017-14491 [CRITICAL] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
USN-3430-1 fixed several vulnerabilities in Dnsmasq. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-20
Red Hat
dnsmasq: heap overflow in the code responsible for building DNS replies
vendor_redhat·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] CWE-122 dnsmasq: heap overflow in the code responsible for building DNS replies
dnsmasq: heap overflow in the code responsible for building DNS replies
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
A heap buffer overflow was found in dnsmasq in the code responsible for building DNS replies. An attacker could send crafted DNS packets to dnsmasq which would cause it to crash or, potentially, execute arbitrary code.
Statement: Red Hat OpenStack Platform includes the dnsmasq-utils RPM which does not contain this flaw's affected code-paths; Red Hat OpenStack Platform is therefore listed as not affected.
However, because all versions of Red Hat OpenStack Platform are based on Red Hat Enterprise Linux, all Red Hat OpenStack Platform users should absolutel
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2017-14492)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DHCPv6 requests. A remote
at
Debian
CVE-2017-14491: dnsmasq - Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cau...
vendor_debian·2017·CVSS 9.8
CVE-2017-14491 [CRITICAL] CVE-2017-14491: dnsmasq - Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cau...
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Scope: local
bookworm: resolved (fixed in 2.78-1)
bullseye: resolved (fixed in 2.78-1)
forky: resolved (fixed in 2.78-1)
sid: resolved (fixed in 2.78-1)
trixie: resolved (fixed in 2.78-1)
GHSA
GHSA-8x2j-2xxw-g7h5: Improper bounds checking in Dnsmasq before 2
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-14513 [CRITICAL] CWE-125 GHSA-8x2j-2xxw-g7h5: Improper bounds checking in Dnsmasq before 2
Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
GHSA
GHSA-m4px-ph3f-7964: Heap-based buffer overflow in dnsmasq before 2
ghsa_unreviewed·2022-04-30
CVE-2017-14491 [CRITICAL] CWE-787 GHSA-m4px-ph3f-7964: Heap-based buffer overflow in dnsmasq before 2
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
OSV
CVE-2017-14491: In do_rfc1035_name of util
osv·2021-03-01
CVE-2017-14491 CVE-2017-14491: In do_rfc1035_name of util
In do_rfc1035_name of util.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when processing a malicious DNS server response with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2019-14513: Improper bounds checking in Dnsmasq before 2
osv·2019-08-01·CVSS 9.8
CVE-2019-14513 [CRITICAL] CVE-2019-14513: Improper bounds checking in Dnsmasq before 2
Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
OSV
CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2
osv·2017-10-04·CVSS 9.8
CVE-2017-14491 [CRITICAL] CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
OSV
dnsmasq vulnerabilities
osv·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] dnsmasq vulnerabilities
dnsmasq vulnerabilities
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2017-14492)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DHCPv6 requests. A remote
attacker could use this issue to cause Dnsmasq to crash, resulting
No detection rules found.
Bugzilla
CVE-2019-14513 dnsmasq: Improper bounds checking leads to a buffer overread
bugzilla·2019-08-09·CVSS 9.8
CVE-2019-14513 [CRITICAL] CVE-2019-14513 dnsmasq: Improper bounds checking leads to a buffer overread
CVE-2019-14513 dnsmasq: Improper bounds checking leads to a buffer overread
Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
Upstream Issue:
https://github.com/Slovejoy/dnsmasq-pre2.76
Discussion:
This commit fixes the problem for me:
http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=d3a8b39c7df2f0debf3b5f274a1c37a9e261f94e
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-14513
---
Statement:
This issue does not affect the versions of dnsmasq as shipped with Red Hat Enterprise L
Bugzilla
CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
bugzilla·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2017-14491 dnsmasq: heap overflow in the code responsible for building DNS replies
bugzilla·2017-09-26·CVSS 9.8
CVE-2017-14491 [CRITICAL] CVE-2017-14491 dnsmasq: heap overflow in the code responsible for building DNS replies
CVE-2017-14491 dnsmasq: heap overflow in the code responsible for building DNS replies
Red Hat Product Security has been made aware of a heap-based buffer overflow affecting the DNS implementation of dnsmasq.
Discussion:
Acknowledgments:
Name: Felix Wilhelm (Google Security Team), Fermin J. Serna (Google Security Team), Gabriel Campana (Google Security Team), Kevin Hamacher (Google Security Team), Ron Bowes (Google Security Team)
---
Further details from the 2.78 pre-release CHANGELOG:
Fix heap overflow in DNS code. This is a potentially serious
security hole. It allows an attacker who can make DNS
requests to dnsmasq, and who controls the contents of
a domain, which is thereby queried, to overflow
(by 2 bytes) a heap buffer and either crash, or
even take control of, dnsmasq.
CVE-20
arXiv
SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity Hypergraphs
arxiv_fulltext·2025-06-02
SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity Hypergraphs
SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity Hypergraphs
Rakesh Podder
0009-0008-7394-1369
Colorado State University
Fort Collins
Colorado
USA
[email protected]
Turgay Caglar
0009-0005-4918-3340
Colorado State University
Fort Collins
Colorado
USA
[email protected]
Shadaab Kawnain Bashir
0009-0008-3090-7187
Colorado State University
Fort Collins
Colorado
USA
[email protected]
Sarath Sreedharan
0000-0002-2299-0178
Colorado State University
Fort Collins
Colorado
USA
[email protected]
Indrajit Ray
0000-0002-3612-7738
Colorado State University
Fort Collins
Colorado
USA
[email protected]
Indrakshi Ray
0000-0002-0714-7676
Colorado State University
Fort Collins
Colorado
USA
indrakshi.ray@c
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
Tenable
How Organizations Can Reduce the Economic Incentives of Vulnerabilities
blogs_tenable·2020-06-10
How Organizations Can Reduce the Economic Incentives of Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Dnsmasq: A Reality Check and Remediation Practices
blogs_trendmicro·2017-10-09
Dnsmasq: A Reality Check and Remediation Practices
IoT
# Dnsmasq: A Reality Check and Remediation Practices
Google Security researchers identified seven vulnerabilities that can allow a remote attacker to execute code on, leak information from, or crash a device running a Dnsmasq version earlier than 2.78, if configured with certain options.
By: Federico Maggi
2017/10/09
Read time: ( words)
Save to Folio
Updated on October 10, 2017, 7:30 PM PDT to add further Trend Micro solutions.
Dnsmasq is the de-facto tool for meeting the DNS/DHCP requirements of small servers and embedded devices. Recently, Google Security researchers identified seven vulnerabilities that can allow a remote attacker to execute code on, leak information from, or crash a device running a Dnsmasq version earlier than 2.78, if configured with certain options.
Base
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4560http://nvidia.custhelp.com/app/answers/detail/a_id/4561http://packetstormsecurity.com/files/144480/Dnsmasq-2-Byte-Heap-Based-Overflow.htmlhttp://thekelleys.org.uk/dnsmasq/CHANGELOGhttp://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=0549c73b7ea6b22a3c49beb4d432f185a81efcbchttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txthttp://www.debian.org/security/2017/dsa-3989http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171103-01-dnsmasq-enhttp://www.securityfocus.com/bid/101085http://www.securityfocus.com/bid/101977http://www.securitytracker.com/id/1039474http://www.ubuntu.com/usn/USN-3430-1http://www.ubuntu.com/usn/USN-3430-2http://www.ubuntu.com/usn/USN-3430-3https://access.redhat.com/errata/RHSA-2017:2836https://access.redhat.com/errata/RHSA-2017:2837https://access.redhat.com/errata/RHSA-2017:2838https://access.redhat.com/errata/RHSA-2017:2839https://access.redhat.com/errata/RHSA-2017:2840https://access.redhat.com/errata/RHSA-2017:2841https://access.redhat.com/security/vulnerabilities/3199382https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/527KNN34RN2SB6MBJG7CKSEBWYE3TJEB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MMPCJOYPPL4B5RBY4U425PWG7EETDTD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXRZ2W6TV6NLUJC5NOFBSG6PZSMDTYPV/https://security.gentoo.org/glsa/201710-27https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.htmlhttps://www.arista.com/en/support/advisories-notices/security-advisories/3577-security-advisory-30https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-449https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-449/https://www.debian.org/security/2017/dsa-3989https://www.exploit-db.com/exploits/42941/https://www.kb.cert.org/vuls/id/973527https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.htmlhttps://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.htmlhttps://www.synology.com/support/security/Synology_SA_17_59_Dnsmasqhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4560http://nvidia.custhelp.com/app/answers/detail/a_id/4561http://packetstormsecurity.com/files/144480/Dnsmasq-2-Byte-Heap-Based-Overflow.htmlhttp://thekelleys.org.uk/dnsmasq/CHANGELOGhttp://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=0549c73b7ea6b22a3c49beb4d432f185a81efcbchttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txthttp://www.debian.org/security/2017/dsa-3989http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171103-01-dnsmasq-enhttp://www.securityfocus.com/bid/101085http://www.securityfocus.com/bid/101977http://www.securitytracker.com/id/1039474http://www.ubuntu.com/usn/USN-3430-1http://www.ubuntu.com/usn/USN-3430-2http://www.ubuntu.com/usn/USN-3430-3https://access.redhat.com/errata/RHSA-2017:2836https://access.redhat.com/errata/RHSA-2017:2837https://access.redhat.com/errata/RHSA-2017:2838https://access.redhat.com/errata/RHSA-2017:2839https://access.redhat.com/errata/RHSA-2017:2840https://access.redhat.com/errata/RHSA-2017:2841https://access.redhat.com/security/vulnerabilities/3199382https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/527KNN34RN2SB6MBJG7CKSEBWYE3TJEB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MMPCJOYPPL4B5RBY4U425PWG7EETDTD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXRZ2W6TV6NLUJC5NOFBSG6PZSMDTYPV/https://security.gentoo.org/glsa/201710-27https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.htmlhttps://www.arista.com/en/support/advisories-notices/security-advisories/3577-security-advisory-30https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-449https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-449/https://www.debian.org/security/2017/dsa-3989https://www.exploit-db.com/exploits/42941/https://www.kb.cert.org/vuls/id/973527https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.htmlhttps://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.htmlhttps://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq
2017-10-04
Published