Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
5.9MEDIUM
EPSS
11.0%
top 6.58%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 3
Latest updateMay 14

Description

dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages6 packages

Debiandnsmasq< 2.78-1+3
NVDnovell/leap42.2, 42.3+1

Also affects: Debian Linux 7.0, 7.1, 9.0, Ubuntu Linux 14.04, 16.04, 17.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p5vm-j7g2-h6cx: dnsmasq before 22022-05-14
OSV
CVE-2017-14494: dnsmasq before 22017-10-03
CVEList
CVE-2017-14494: dnsmasq before 22017-10-02

💥Exploits & PoCs

1
Exploit-DB
Dnsmasq < 2.78 - Information Leak2017-10-02

📋Vendor Advisories

4
Ubuntu
Dnsmasq vulnerabilities2017-10-03
Red Hat
dnsmasq: information leak in the DHCPv6 relay code2017-10-02
Ubuntu
Dnsmasq vulnerabilities2017-10-02
Debian
CVE-2017-14494: dnsmasq - dnsmasq before 2.78, when configured as a relay, allows remote attackers to obta...2017

💬Community

2
Bugzilla
CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]2017-10-02
Bugzilla
CVE-2017-14494 dnsmasq: information leak in the DHCPv6 relay code2017-09-26
CVE-2017-14494 (MEDIUM CVSS 5.9) | dnsmasq before 2.78 | cvebase.io