Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SciLinux: SLSA-2017-2838-1 Critical: Dnsmasq Buffer Overflow Threat

Scientific Large Esm H446
A heap buffer overflow was found in dnsmasq in the code responsible for building DNS replies. An attacker could send crafted DNS packets to dnsmasq which would cause it to crash or, potentially, execute arbitrary code. (CVE-2017-14491) SL6 x86_64 dnsmasq-debuginfo-2.48-18.el6_9.x86_64.rpm dnsmasq-2.48-18.el6_9.x86_64.rpm dnsmasq-utils-2.48-18.el6_9.x86_64.rpm i386 dnsmasq- [More...]
Synopsis:          Critical: dnsmasq security update
Advisory ID:       SLSA-2017:2838-1
Issue Date:        2017-10-02
CVE Numbers:       CVE-2017-14491
--

Security Fix(es):

* A heap buffer overflow was found in dnsmasq in the code responsible for
building DNS replies. An attacker could send crafted DNS packets to
dnsmasq which would cause it to crash or, potentially, execute arbitrary
code. (CVE-2017-14491)
--

SL6
  x86_64
    dnsmasq-debuginfo-2.48-18.el6_9.x86_64.rpm
    dnsmasq-2.48-18.el6_9.x86_64.rpm
    dnsmasq-utils-2.48-18.el6_9.x86_64.rpm
  i386
    dnsmasq-debuginfo-2.48-18.el6_9.i686.rpm
    dnsmasq-2.48-18.el6_9.i686.rpm
    dnsmasq-utils-2.48-18.el6_9.i686.rpm

- Scientific Linux Development Team