vendor:
dnsmasq-utils
by:
Josue Encinar
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: dnsmasq-utils
Affected Version From: 2.79
Affected Version To: 2.79
Patch Exists: YES
Related CWE: N/A
CPE: 2.3:a:dnsmasq:dnsmasq_utils:2.79
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2020
dnsmasq-utils 2.79-1 – ‘dhcp_release’ Denial of Service (PoC)
The vulnerability exists due to a boundary error when handling user-supplied data, specifically when handling the 'dhcp_release' command. By supplying an overly long argument, a buffer overflow can be triggered, resulting in a denial of service.
Mitigation:
Upgrade to the latest version of dnsmasq-utils.