Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE 11-SP4: 2017:2619-1 Important: dnsmasq DoS Threats Addressed

suse
Calendar Grey October 2, 2017
Dist Suse Esm H88
The latest release for dnsmasq resolves significant vulnerabilities that could be exploited. Ensure your security by applying the newest update!
An update that fixes 8 vulnerabilities is now available

Summary

This update for dnsmasq fixes the following security issues: - CVE-2017-14491: 2 byte heap based overflow. [bsc#1060354] - CVE-2017-14492: heap based overflow. [bsc#1060355] - CVE-2017-14493: stack based overflow. [bsc#1060360] - CVE-2017-14494: DHCP - info leak. [bsc#1060361] - CVE-2017-14495: DNS - OOM DoS. [bsc#1060362] - CVE-2017-14496: DNS - DoS Integer underflow. [bsc#1060364] This update brings a (small) potential incompatibility in the handling of "basename" in --pxe-service. Please read the CHANGELOG and the documentation if you are using this option. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-dnsmasq-13294=1

References

#1060354 #1060355 #1060360 #1060361 #1060362

#1060364

Cross- CVE-2015-3294 CVE-2015-8899 CVE-2017-14491

CVE-2017-14492 CVE-2017-14493 CVE-2017-14494

CVE-2017-14495 CVE-2017-14496

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2015-3294.html

https://www.suse.com/security/cve/CVE-2015-8899.html

https://www.suse.com/security/cve/CVE-2017-14491.html

https://www.suse.com/security/cve/CVE-2017-14492.html

https://www.suse.com/security/cve/CVE-2017-14493.html

https://www.suse.com/security/cve/CVE-2017-14494.html

https://www.suse.com/security/cve/CVE-2017-14495.html

https://www.suse.com/security/cve/CVE-2017-14496.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2619-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here