ZeroHour

CVE-2017-13704

CVSS 3.0
7.5 high
EPSS
65%p99
Published
()
Modified
Description

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

Vendors
canonicaldebianfedoraprojectnovellredhatthekelleys
Products
ubuntu linux, debian linux, fedora, leap, enterprise linux desktop, enterprise linux server, enterprise linux workstation, dnsmasq
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news