CVE-2017-14494
published 2017-10-03CVE-2017-14494: dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded…
PriorityP260medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EXPLOIT
EPSS
67.55%
99.2th percentile
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | dnsmasq | < dnsmasq 2.78-1 (bookworm) | dnsmasq 2.78-1 (bookworm) |
| novell | leap | — | — |
| novell | leap | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| thekelleys | dnsmasq | <= 2.77 | — |
| thekelleys | dnsmasq | >= 0 < 2.78-1 | 2.78-1 |
| thekelleys | dnsmasq | >= 0 < 2.78-1 | 2.78-1 |
| thekelleys | dnsmasq | >= 0 < 2.78-1 | 2.78-1 |
| thekelleys | dnsmasq | >= 0 < 2.78-1 | 2.78-1 |
| thekelleys | dnsmasq | >= 0 < 2.68-1ubuntu0.2 | 2.68-1ubuntu0.2 |
| thekelleys | dnsmasq | >= 0 < 2.75-1ubuntu0.16.04.3 | 2.75-1ubuntu0.16.04.3 |
Detection & IOCsextracted from sources · hover to see the quote
urlhttp://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=33e3f1029c9ec6c63e430ff51063a6301d4b2262↗
- →Detect crafted DHCPv6 RELAY-FORW packets (message type 12) sent to UDP port 547 where the OPTION6_RELAY_MSG (option 9) length field exceeds the actual packet buffer size — this is the memory-leak trigger condition. ↗
- →Monitor for DHCPv6 relay responses (from dnsmasq acting as relay) that are significantly larger than the originating request — the PoC leaks up to 32 KB of process memory starting at buffer+38. ↗
- →Flag inbound DHCPv6 packets on UDP/547 containing message type 0x0c (RELAY-FORW) with option type 9 (RELAY_MSG) whose declared length field is larger than the remaining packet bytes. ↗
- →Exploitation requires the attacker to be on the local network segment; prioritise monitoring on internal DHCPv6 relay-enabled interfaces rather than internet-facing ones. ↗
- ·This vulnerability only affects dnsmasq when configured as a DHCPv6 relay; instances not acting as a relay are not exploitable. ↗
- ·dnsmasq on RHEL 5 and RHEL 6 does not include the DHCPv6 relay code and is therefore not affected; detection rules targeting those platforms are unnecessary. ↗
- ·The exploit requires knowledge of the target's DUID (DHCPv6 Unique Identifier); absence of an automated DUID-discovery method slightly raises the bar for opportunistic attackers. ↗
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p5vm-j7g2-h6cx: dnsmasq before 2
ghsa_unreviewed·2022-05-14
CVE-2017-14494 [MEDIUM] CWE-200 GHSA-p5vm-j7g2-h6cx: dnsmasq before 2
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
OSV
CVE-2017-14494: dnsmasq before 2
osv·2017-10-03·CVSS 5.9
CVE-2017-14494 [MEDIUM] CVE-2017-14494: dnsmasq before 2
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
OSV
dnsmasq vulnerabilities
osv·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] dnsmasq vulnerabilities
dnsmasq vulnerabilities
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2017-14492)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DHCPv6 requests. A remote
attacker could use this issue to cause Dnsmasq to crash, resulting
Ubuntu
Dnsmasq regression
vendor_ubuntu·2018-01-04·CVSS 9.8
[CRITICAL] Dnsmasq regression
Title: Dnsmasq regression
Summary: USN-3430-2 introduced regression in Dnsmasq.
USN-3430-2 fixed several vulnerabilities. The update introduced a new
regression that breaks DNS resolution. This update addresses the problem.
We apologize for the inconvenience.
Original advisory details:
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2017-10-03·CVSS 9.8
CVE-2017-14491 [CRITICAL] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
USN-3430-1 fixed several vulnerabilities in Dnsmasq. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-20
Red Hat
dnsmasq: information leak in the DHCPv6 relay code
vendor_redhat·2017-10-02·CVSS 5.9
CVE-2017-14494 [MEDIUM] CWE-125 dnsmasq: information leak in the DHCPv6 relay code
dnsmasq: information leak in the DHCPv6 relay code
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
An information leak was found in dnsmasq in the DHCPv6 relay code. An attacker on the local network could send crafted DHCPv6 packets to dnsmasq causing it to forward the contents of process memory, potentially leaking sensitive data.
Statement: Red Hat OpenStack Platform includes the dnsmasq-utils RPM which does not contain this flaw's affected code-paths; Red Hat OpenStack Platform is therefore listed as not affected.
However, because all versions of Red Hat OpenStack Platform are based on Red Hat Enterprise Linux, all Red Hat OpenStack Platform users should absolutel
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2017-14492)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DHCPv6 requests. A remote
at
Debian
CVE-2017-14494: dnsmasq - dnsmasq before 2.78, when configured as a relay, allows remote attackers to obta...
vendor_debian·2017·CVSS 5.9
CVE-2017-14494 [MEDIUM] CVE-2017-14494: dnsmasq - dnsmasq before 2.78, when configured as a relay, allows remote attackers to obta...
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
Scope: local
bookworm: resolved (fixed in 2.78-1)
bullseye: resolved (fixed in 2.78-1)
forky: resolved (fixed in 2.78-1)
sid: resolved (fixed in 2.78-1)
trixie: resolved (fixed in 2.78-1)
No detection rules found.
Bugzilla
CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
bugzilla·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2017-14494 dnsmasq: information leak in the DHCPv6 relay code
bugzilla·2017-09-26·CVSS 5.9
CVE-2017-14494 [MEDIUM] CVE-2017-14494 dnsmasq: information leak in the DHCPv6 relay code
CVE-2017-14494 dnsmasq: information leak in the DHCPv6 relay code
Red Hat Product Security has been made aware of an information leak vulnerability affecting the DHCP implementation of dnsmasq.
Discussion:
Acknowledgments:
Name: Felix Wilhelm (Google Security Team), Fermin J. Serna (Google Security Team), Gabriel Campana (Google Security Team), Kevin Hamacher (Google Security Team), Ron Bowes (Google Security Team)
---
Versions of dnsmasq shipped with Red Hat Enterprise Linux 6 and 5 do not include the DHCPv6 code which includes this flaw.
---
Further details from the 2.78 pre-release CHANGELOG:
Fix information leak in DHCPv6. A crafted DHCPv6 packet can
cause dnsmasq to forward memory from outside the packet
buffer to a DHCPv6 server when acting as a relay.
CVE-2017-14494 applies
Trendmicro
Dnsmasq: A Reality Check and Remediation Practices
blogs_trendmicro·2017-10-09
Dnsmasq: A Reality Check and Remediation Practices
IoT
# Dnsmasq: A Reality Check and Remediation Practices
Google Security researchers identified seven vulnerabilities that can allow a remote attacker to execute code on, leak information from, or crash a device running a Dnsmasq version earlier than 2.78, if configured with certain options.
By: Federico Maggi
2017/10/09
Read time: ( words)
Save to Folio
Updated on October 10, 2017, 7:30 PM PDT to add further Trend Micro solutions.
Dnsmasq is the de-facto tool for meeting the DNS/DHCP requirements of small servers and embedded devices. Recently, Google Security researchers identified seven vulnerabilities that can allow a remote attacker to execute code on, leak information from, or crash a device running a Dnsmasq version earlier than 2.78, if configured with certain options.
Base
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4561http://thekelleys.org.uk/dnsmasq/CHANGELOGhttp://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=33e3f1029c9ec6c63e430ff51063a6301d4b2262http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txthttp://www.debian.org/security/2017/dsa-3989http://www.securityfocus.com/bid/101085http://www.securitytracker.com/id/1039474http://www.ubuntu.com/usn/USN-3430-1http://www.ubuntu.com/usn/USN-3430-2https://access.redhat.com/errata/RHSA-2017:2836https://access.redhat.com/errata/RHSA-2017:2837https://access.redhat.com/security/vulnerabilities/3199382https://security.gentoo.org/glsa/201710-27https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.htmlhttps://www.exploit-db.com/exploits/42944/https://www.kb.cert.org/vuls/id/973527https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.htmlhttps://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.htmlhttps://www.synology.com/support/security/Synology_SA_17_59_Dnsmasqhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4561http://thekelleys.org.uk/dnsmasq/CHANGELOGhttp://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=33e3f1029c9ec6c63e430ff51063a6301d4b2262http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txthttp://www.debian.org/security/2017/dsa-3989http://www.securityfocus.com/bid/101085http://www.securitytracker.com/id/1039474http://www.ubuntu.com/usn/USN-3430-1http://www.ubuntu.com/usn/USN-3430-2https://access.redhat.com/errata/RHSA-2017:2836https://access.redhat.com/errata/RHSA-2017:2837https://access.redhat.com/security/vulnerabilities/3199382https://security.gentoo.org/glsa/201710-27https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.htmlhttps://www.exploit-db.com/exploits/42944/https://www.kb.cert.org/vuls/id/973527https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.htmlhttps://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.htmlhttps://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq
2017-10-03
Published