vendor:
dnsmasq
by:
Fermin J. Serna, Felix Wilhelm, Gabriel Campana, Kevin Hamacher, Gynvael Coldwind, Ron Bowes
5.9
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: dnsmasq
Affected Version From: dnsmasq 2.78
Affected Version To: dnsmasq 2.78
Patch Exists: YES
Related CWE: CVE-2017-14494
CPE: a:thekelleys:dnsmasq:2.78
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3430-3/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/dnsmasq-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-14494/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2017-14494/
Platforms Tested:
2017
CVE-2017-14494
The exploit allows an attacker to cause a denial of service (DoS) by sending a specially crafted packet to the dnsmasq DHCPv6 server. By exploiting this vulnerability, an attacker can crash the server, causing a loss of service for legitimate users.
Mitigation:
Apply the patch provided by the vendor or update to a version that includes the fix.