dnsmasq: memory leak in the create_helper() function in /src/helper.c
Published Jan 7, 2020
3.7
LOWCVSS 3.1
EPSS 2.65%
Description
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
Affected products
-
- Version before 2.81StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Dnsmasq Project | Dnsmasq | n/a |
|
Configuration 1
- < 2.81
Configuration 2
- 31
No data.
Red Hat Enterprise Linux 7
dnsmasq-0:2.76-16.el7
Fixed · RHSA-2020:3878
Red Hat Enterprise Linux 8
dnsmasq-0:2.79-11.el8
Fixed · RHSA-2020:1715
Red Hat Enterprise Linux 5
dnsmasq
Out of support scope
Red Hat Enterprise Linux 6
dnsmasq
Out of support scope
Red Hat OpenStack Platform 10 (Newton)
dnsmasq
Will not fix
Red Hat OpenStack Platform 13 (Queens)
dnsmasq
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
dnsmasq
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | dnsmasq-0:2.76-16.el7 | Fixed | RHSA-2020:3878 |
| Red Hat Enterprise Linux 8 | dnsmasq-0:2.79-11.el8 | Fixed | RHSA-2020:1715 |
| Red Hat Enterprise Linux 5 | dnsmasq | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | dnsmasq | Out of support scope | n/a |
| Red Hat OpenStack Platform 10 (Newton) | dnsmasq | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | dnsmasq | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | dnsmasq | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In Red Hat OpenStack Platform, which currently supports Red Hat Enterprise Linux 7.7, the dnsmasq package is pulled directly from the rhel-7-server-rpms channel. Red Hat OpenStack Platform's version is therefore unused, please ensure that the underlying Red Hat Enterprise Linux dnsmasq package is current.
References (7)
- http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=69bc94779c2f035a9fffdb5327a54c3aeca73ed5 x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2019-14834 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1764425 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14834 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JU474LT66BHNVFG5C4GEV3VTZNAEJ3BS/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-14834
- https://www.cve.org/CVERecord?id=CVE-2019-14834
| Link | Providers | Tags |
|---|---|---|
| http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=69bc94779c2f035a9fffdb5327a54c3aeca73ed5 | x_refsource_CONFIRM | |
| https://access.redhat.com/security/cve/CVE-2019-14834 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1764425 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14834 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JU474LT66BHNVFG5C4GEV3VTZNAEJ3BS/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14834 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-14834 |
Change history (0)
No recorded changes yet.