Back

CRITICAL

dnsmasq: heap overflow in the code responsible for building DNS replies

Published Oct 2, 2017

Description

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform includes the dnsmasq-utils RPM which does not contain this flaw's affected code-paths; Red Hat OpenStack Platform is therefore listed as not affected. However, because all versions of Red Hat OpenStack Platform are based on Red Hat Enterprise Linux, all Red Hat OpenStack Platform users should absolutely upgrade the dnsmasq RPM from Red Hat Enterprise Linux as a matter of urgency using standard update mechanisms (such as 'yum update' or 'openstack overcloud update').

Metrics

References (43)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 2, 2017
Updated Aug 5, 2024
Reserved Sep 15, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Oct 2, 2017