Denial of Service Vulnerability in dnsmasq 2.78 and earlier

Denial of Service Vulnerability in dnsmasq 2.78 and earlier

CVE-2017-13704 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

Learn more about our Web Application Penetration Testing UK.