Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14496. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit triggers a heap-based buffer overflow in dnsmasq via a crafted DNS packet, leading to a denial-of-service (DoS) condition. The vulnerability arises from incorrect handling of EDNS0 options when specific configuration flags are enabled.
Description
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
Exploits (1)
This exploit triggers a heap-based buffer overflow in dnsmasq via a crafted DNS packet, leading to a denial-of-service (DoS) condition. The vulnerability arises from incorrect handling of EDNS0 options when specific configuration flags are enabled.
References (22)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H