CVE-2017-14491
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Affected (46)
Products: Thekelleys: Dnsmasq · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation · Canonical: Ubuntu Linux · +9 more
Show all products
Thekelleys: Dnsmasq · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation · Canonical: Ubuntu Linux · Debian: Debian Linux · Opensuse: Leap · Suse: Linux Enterprise Debuginfo, Linux Enterprise Point Of Sale, Linux Enterprise Server · Nvidia: Linux For Tegra, Geforce Experience · Huawei: Honor V9 Play Firmware · Arista: Eos · Siemens: Ruggedcom Rm1224 Firmware, Scalance M 800 Firmware, Scalance S615 Firmware, Scalance W1750d Firmware · Arubanetworks: Arubaos · Synology: Diskstation Manager, Router Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.77 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.0 | |
| Version 6.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 sp3 | |
| Version 11 sp3 | |
| Version 11 sp3 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before r21.6 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Jetson Tk1 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before r24.2.2 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Jetson Tx1 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.10.0.55 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before jimmy-al00ac00b135 |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor V9 Play | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rm1224 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M 800 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance S615 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.5.1.5 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance W1750d | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.3.1 to 6.3.1.25 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.2 | |
| Version 1.1 |
References (80)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
MitigationThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.