VYPR

rpm package

opensuse/dnsmasq&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/dnsmasq&distro=openSUSE%20Tumbleweed

Vulnerabilities (29)

  • CVE-2017-15107HigJan 23, 2018
    affected < 2.86-1.1fixed 2.86-1.1

    A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.

  • CVE-2017-14491CriOct 4, 2017
    affected < 2.86-1.1fixed 2.86-1.1

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

  • CVE-2017-14496HigOct 3, 2017
    affected < 2.86-1.1fixed 2.86-1.1

    Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

  • CVE-2017-14495HigOct 3, 2017
    affected < 2.86-1.1fixed 2.86-1.1

    Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.

  • CVE-2017-14494MedOct 3, 2017
    affected < 2.86-1.1fixed 2.86-1.1

    dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.

  • CVE-2017-14493CriOct 3, 2017
    affected < 2.86-1.1fixed 2.86-1.1

    Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.

  • CVE-2017-14492CriOct 3, 2017
    affected < 2.86-1.1fixed 2.86-1.1

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.

  • CVE-2015-8899HigJun 30, 2016
    affected < 2.76-1.3fixed 2.76-1.3

    Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.

  • CVE-2015-3294May 8, 2015
    affected < 2.76-1.3fixed 2.76-1.3

    The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.

Page 2 of 2