CVE-2017-13704
Summary
| CVE | CVE-2017-13704 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-03 01:29:00 UTC |
| Updated | 2023-11-07 02:38:00 UTC |
| Description | In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.04 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.1 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.1 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 27 | All | All | All |
| Operating System | Fedoraproject | Fedora | 27 | All | All | All |
| Operating System | Novell | Leap | 42.2 | All | All | All |
| Operating System | Novell | Leap | 42.3 | All | All | All |
| Operating System | Novell | Leap | 42.2 | All | All | All |
| Operating System | Novell | Leap | 42.3 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 7.0 | All | All | All |
| Application | Thekelleys | Dnsmasq | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| thekelleys.org.uk/dnsmasq/CHANGELOG | CONFIRM | thekelleys.org.uk | Release Notes, Vendor Advisory |
| RETIRED: Multiple Siemens SCALANCE Products Multiple Security Vulnerabilities | BID | www.securityfocus.com | |
| Dnsmasq Multiple Flaws Let Remote Users Execute Arbitrary Code, Deny Service, and Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Synology-SA-17:59 Dnsmasq | Synology Inc. | CONFIRM | www.synology.com | |
| [SECURITY] Fedora 27 Update: dnsmasq-2.77-7.fc27 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| thekelleys.org.uk Git - dnsmasq.git/commit | thekelleys.org.uk | ||
| cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf | CONFIRM | cert-portal.siemens.com | |
| dnsmasq: Multiple Critical and Important vulnerabilities - Red Hat Customer Portal | CONFIRM | access.redhat.com | Issue Tracking, Third Party Advisory |
| Dnsmasq VU#973527 Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [Dnsmasq-discuss] IMPORTANT SECURITY INFORMATION. | www.mail-archive.com | ||
| [SECURITY] Fedora 27 Update: dnsmasq-2.77-7.fc27 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| Google Online Security Blog: Behind the Masq: Yet more DNS, and DHCP, vulnerabilities | MISC | security.googleblog.com | Third Party Advisory |
| [Dnsmasq-discuss] Announce: dnsmasq-2.78. | www.mail-archive.com | ||
| thekelleys.org.uk Git - dnsmasq.git/commit | CONFIRM | thekelleys.org.uk | Patch, Vendor Advisory |
| [Dnsmasq-discuss] IMPORTANT SECURITY INFORMATION. | MLIST | www.mail-archive.com | Mailing List, Third Party Advisory |
| [Dnsmasq-discuss] Announce: dnsmasq-2.78. | MLIST | www.mail-archive.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.