VYPR
Medium severity5.9NVD Advisory· Published Oct 3, 2017· Updated May 13, 2026

CVE-2017-14494

CVE-2017-14494

Description

dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.

Affected products

12
  • cpe:2.3:o:debian:debian_linux:7.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:7.1:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*
  • Novell/Leap2 versions
    cpe:2.3:o:novell:leap:42.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:novell:leap:42.2:*:*:*:*:*:*:*
    • cpe:2.3:o:novell:leap:42.3:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:*
    Range: <=2.77

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

19

News mentions

0

No linked articles in our index yet.