CVE-2017-13704
HIGHCanonical Ubuntu Linux < 2.77 - Improper Input Validation
Title source: ruleDescription
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
References (12)
Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1039474
Various Sources x_refsource_confirm
https://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq
Issue Tracking, Third Party Advisory x_refsource_confirm
https://access.redhat.com/security/vulnerabilities/3199382
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/101085
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TK6DWC53WSU6633EVZL7H4PCWBYHMHK/
Mailing List mailing-list
x_refsource_mlist
https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.html
Various Sources x_refsource_confirm
http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=63437ffbb58837b214b4b92cb1c54bc5f3279928
Release Notes, Vendor Advisory x_refsource_confirm
http://thekelleys.org.uk/dnsmasq/CHANGELOG
Third Party Advisory x_refsource_misc
https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html
Mailing List mailing-list
x_refsource_mlist
https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.html
Vendor Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/101977
Scores
CVSS v3
7.5
EPSS
0.7932
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (13)
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
17.04
debian/debian_linux
7.0
debian/debian_linux
7.1
debian/debian_linux
9.0
fedoraproject/fedora
27
novell/leap
42.2
novell/leap
42.3
redhat/enterprise_linux_desktop
7.0
... and 3 more
Published
Oct 03, 2017
Tracked Since
Feb 18, 2026