CVE-2017-14496
published 2017-10-03CVE-2017-14496: Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote…
PriorityP262high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
66.35%
99.2th percentile
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | dnsmasq | < dnsmasq 2.78-1 (bookworm) | dnsmasq 2.78-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| novell | leap | — | — |
| novell | leap | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| thekelleys | dnsmasq | <= 2.77 | — |
| thekelleys | dnsmasq | >= 0 < 2.78-1 | 2.78-1 |
| thekelleys | dnsmasq | >= 0 < 2.78-1 | 2.78-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition requires dnsmasq to be running with --add-mac, --add-cpe-id, or --add-subnet option; only crafted DNS requests sent to those configurations will trigger the integer underflow in add_pseudoheader ↗
- →The vulnerability is in the EDNS0 code path; monitor for malformed/oversized EDNS0 OPT records in DNS UDP traffic that cause dnsmasq to crash (process termination/restart events) ↗
- →The PoC sends a single crafted UDP DNS packet; a dnsmasq crash immediately following receipt of a single DNS request from an external IP is a strong indicator of exploitation ↗
- ·Vulnerability is only exploitable when dnsmasq is configured with at least one of the options: --add-mac, --add-cpe-id, or --add-subnet; default configurations are not affected ↗
- ·Red Hat OpenStack Platform dnsmasq-utils RPM does not contain the affected code paths and is not vulnerable, but the underlying dnsmasq RPM from RHEL should still be patched ↗
- ·Fixed in dnsmasq 2.78; Debian packages resolved in version 2.78-1 across all tracked suites ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224 (Update C)
cisa_ics·2018-05-10·CVSS 7.5
[HIGH] Siemens SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224 (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224 (Update C)
Last RevisedOctober 13, 2020
Alert CodeICSA-17-332-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Siemens
--------- Begin Update C Part 1 of 3 --------
- Equipment: SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224
--------- End Update C Part 1 of 3 --------
- Vulnerabilities: Resource Exhaustion, Improper Restriction of Operations within the Bounds of a Memory Buffer
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the up
Ubuntu
Dnsmasq regression
vendor_ubuntu·2018-01-04·CVSS 9.8
[CRITICAL] Dnsmasq regression
Title: Dnsmasq regression
Summary: USN-3430-2 introduced regression in Dnsmasq.
USN-3430-2 fixed several vulnerabilities. The update introduced a new
regression that breaks DNS resolution. This update addresses the problem.
We apologize for the inconvenience.
Original advisory details:
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2017-10-03·CVSS 9.8
CVE-2017-14491 [CRITICAL] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
USN-3430-1 fixed several vulnerabilities in Dnsmasq. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-20
Red Hat
dnsmasq: integer underflow leading to buffer over-read in the EDNS0 code
vendor_redhat·2017-10-02·CVSS 7.5
CVE-2017-14496 [HIGH] CWE-190 dnsmasq: integer underflow leading to buffer over-read in the EDNS0 code
dnsmasq: integer underflow leading to buffer over-read in the EDNS0 code
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
An integer underflow flaw leading to a buffer over-read was found in dnsmasq in the EDNS0 code. An attacker could send crafted DNS packets to dnsmasq which would cause it to crash. This issue only affected configurations using one of the options: add-mac, add-cpe-id, or add-subnet.
Statement: Red Hat OpenStack Platform includes the dnsmasq-utils RPM which does not contain this flaw's affected code-paths; Red Hat OpenStack Platform is therefore listed as not affected.
However, because all versi
Ubuntu
Dnsmasq vulnerabilities
vendor_ubuntu·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] Dnsmasq vulnerabilities
Title: Dnsmasq vulnerabilities
Summary: Several security issues were fixed in Dnsmasq.
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2017-14492)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DHCPv6 requests. A remote
at
Android
CVE-2017-14496: Android Security Bulletin 2017-10-01
CVE: CVE-2017-14496
Severity: HIGH
Type: RCE
Affected AOSP versions: 4
vendor_android·2017-10-01·CVSS 7.5
CVE-2017-14496 [HIGH] CVE-2017-14496: Android Security Bulletin 2017-10-01
CVE: CVE-2017-14496
Severity: HIGH
Type: RCE
Affected AOSP versions: 4
Android Security Bulletin 2017-10-01
CVE: CVE-2017-14496
Severity: HIGH
Type: RCE
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0
References: A-64575136
[2]
Debian
CVE-2017-14496: dnsmasq - Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when...
vendor_debian·2017·CVSS 7.5
CVE-2017-14496 [HIGH] CVE-2017-14496: dnsmasq - Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when...
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
Scope: local
bookworm: resolved (fixed in 2.78-1)
bullseye: resolved (fixed in 2.78-1)
forky: resolved (fixed in 2.78-1)
sid: resolved (fixed in 2.78-1)
trixie: resolved (fixed in 2.78-1)
GHSA
GHSA-68rc-w788-2jr7: Integer underflow in the add_pseudoheader function in dnsmasq before 2
ghsa_unreviewed·2022-05-14
CVE-2017-14496 [HIGH] CWE-191 GHSA-68rc-w788-2jr7: Integer underflow in the add_pseudoheader function in dnsmasq before 2
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
OSV
CVE-2017-14496: Integer underflow in the add_pseudoheader function in dnsmasq before 2
osv·2017-10-03·CVSS 7.5
CVE-2017-14496 [HIGH] CVE-2017-14496: Integer underflow in the add_pseudoheader function in dnsmasq before 2
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
OSV
dnsmasq vulnerabilities
osv·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] dnsmasq vulnerabilities
dnsmasq vulnerabilities
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DNS requests. A remote attacker
could use this issue to cause Dnsmasq to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2017-14491)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled IPv6 router advertisements. A
remote attacker could use this issue to cause Dnsmasq to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2017-14492)
Felix Wilhelm, Fermin J. Serna, Gabriel Campana and Kevin Hamacher
discovered that Dnsmasq incorrectly handled DHCPv6 requests. A remote
attacker could use this issue to cause Dnsmasq to crash, resulting
No detection rules found.
Bugzilla
CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
bugzilla·2017-10-02·CVSS 9.8
CVE-2017-14491 [CRITICAL] CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 dnsmasq: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2017-14496 dnsmasq: integer underflow leading to buffer over-read in the EDNS0 code
bugzilla·2017-09-26·CVSS 7.5
CVE-2017-14496 [HIGH] CVE-2017-14496 dnsmasq: integer underflow leading to buffer over-read in the EDNS0 code
CVE-2017-14496 dnsmasq: integer underflow leading to buffer over-read in the EDNS0 code
Red Hat Product Security has been made aware of a Denial of Service vulnerability affecting the DNS implementation of dnsmasq.
Discussion:
Acknowledgments:
Name: Felix Wilhelm (Google Security Team), Fermin J. Serna (Google Security Team), Gabriel Campana (Google Security Team), Kevin Hamacher (Google Security Team), Ron Bowes (Google Security Team)
---
Versions of dnsmasq shipped with Red Hat Enterprise Linux 6 and 5 do not include the EDNS0 code which includes this flaw.
---
Further details from the 2.78 pre-release CHANGELOG:
Fix DoS in DNS. Invalid boundary checks in the
add_pseudoheader function allows a memcpy call with negative
size An attacker which can send malicious DNS queries
to dns
Trendmicro
Dnsmasq: A Reality Check and Remediation Practices
blogs_trendmicro·2017-10-09
Dnsmasq: A Reality Check and Remediation Practices
IoT
# Dnsmasq: A Reality Check and Remediation Practices
Google Security researchers identified seven vulnerabilities that can allow a remote attacker to execute code on, leak information from, or crash a device running a Dnsmasq version earlier than 2.78, if configured with certain options.
By: Federico Maggi
2017/10/09
Read time: ( words)
Save to Folio
Updated on October 10, 2017, 7:30 PM PDT to add further Trend Micro solutions.
Dnsmasq is the de-facto tool for meeting the DNS/DHCP requirements of small servers and embedded devices. Recently, Google Security researchers identified seven vulnerabilities that can allow a remote attacker to execute code on, leak information from, or crash a device running a Dnsmasq version earlier than 2.78, if configured with certain options.
Base
arXiv
Context-aware Failure-oblivious Computing as a Means of Preventing Buffer Overflows
arxiv_fulltext·2018-11-22
Context-aware Failure-oblivious Computing as a Means of Preventing Buffer Overflows
Context-aware Failure-oblivious Computing as a Means of Preventing Buffer OverflowsThe final authenticated version is available online at https://doi.org/10.1007/978-3-030-02744-5_29. We thank Oracle Labs for funding this research. We thank Gerg\"o Barany, Roland Yap, and Fabio Niephaus for their useful feedback on an early draft of this paper. We thank Ingrid Abfalter for proofreading and editorial assistance.
Manuel Rigger1
Daniel Pekarek1
Hanspeter M\"ossenb\"ock1
M. Rigger et al.
Johannes Kepler University Linz, Austria
\manuel.rigger,daniel.pekarek,hanspeter.moessenboeck\@jku.at
## Abstract
In languages like C, buffer overflows are widespread.
A common mitigation technique is to use tools that detect them during execution and abort the program to prevent data leakage or the diversi
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4561http://thekelleys.org.uk/dnsmasq/CHANGELOGhttp://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=897c113fda0886a28a986cc6ba17bb93bd6cb1c7http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txthttp://www.debian.org/security/2017/dsa-3989http://www.securityfocus.com/bid/101085http://www.securityfocus.com/bid/101977http://www.securitytracker.com/id/1039474http://www.ubuntu.com/usn/USN-3430-1http://www.ubuntu.com/usn/USN-3430-2https://access.redhat.com/errata/RHSA-2017:2836https://access.redhat.com/security/vulnerabilities/3199382https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdfhttps://security.gentoo.org/glsa/201710-27https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.htmlhttps://source.android.com/security/bulletin/2017-10-01https://www.exploit-db.com/exploits/42946/https://www.kb.cert.org/vuls/id/973527https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.htmlhttps://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.htmlhttps://www.synology.com/support/security/Synology_SA_17_59_Dnsmasqhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4561http://thekelleys.org.uk/dnsmasq/CHANGELOGhttp://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=897c113fda0886a28a986cc6ba17bb93bd6cb1c7http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txthttp://www.debian.org/security/2017/dsa-3989http://www.securityfocus.com/bid/101085http://www.securityfocus.com/bid/101977http://www.securitytracker.com/id/1039474http://www.ubuntu.com/usn/USN-3430-1http://www.ubuntu.com/usn/USN-3430-2https://access.redhat.com/errata/RHSA-2017:2836https://access.redhat.com/security/vulnerabilities/3199382https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdfhttps://security.gentoo.org/glsa/201710-27https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.htmlhttps://source.android.com/security/bulletin/2017-10-01https://www.exploit-db.com/exploits/42946/https://www.kb.cert.org/vuls/id/973527https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.htmlhttps://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.htmlhttps://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq
2017-10-03
Published