Exploitation Summary
EIP tracks 2 public exploits for CVE-2017-14493. PoCs published by Google Security Research, pupiles.
AI-analyzed exploit summary This exploit triggers a stack-based buffer overflow in dnsmasq's DHCPv6 relay handling by sending a malformed packet with an oversized OPTION6_CLIENT_MAC field. The PoC causes a segmentation fault, demonstrating the vulnerability described in CVE-2017-14493.
Description
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
Exploits (2)
This exploit triggers a stack-based buffer overflow in dnsmasq's DHCPv6 relay handling by sending a malformed packet with an oversized OPTION6_CLIENT_MAC field. The PoC causes a segmentation fault, demonstrating the vulnerability described in CVE-2017-14493.
This is a Python-based exploit for CVE-2017-14493, a buffer overflow vulnerability in DNSmasq. The PoC constructs a malicious DHCPv6 packet to trigger a stack-based buffer overflow, leading to remote code execution (RCE) via ROP chain manipulation.
References (20)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H