Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201710-27 ] Dnsmasq: Multiple vulnerabilities
Date: Mon, 23 Oct 2017 02:42:51
Message-Id: 71852476.2uN2clBKvu@localhost.localdomain
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201710-27
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Dnsmasq: Multiple vulnerabilities
9 Date: October 23, 2017
10 Bugs: #632692
11 ID: 201710-27
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Dnsmasq, the worst of which
19 may allow remote attackers to execute arbitrary code.
20
21 Background
22 ==========
23
24 Dnsmasq is a lightweight and easily-configurable DNS forwarder and DHCP
25 server.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-dns/dnsmasq < 2.78 >= 2.78
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Dnsmasq. Please review
39 the references below for details.
40
41 Impact
42 ======
43
44 A remote attacker could execute arbitrary code or cause a Denial of
45 Service condition via crafted DNS, IPv6, or DHCPv6 packets.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All Dnsmasq users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot --verbose ">=net-dns/dnsmasq-2.78"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2017-14491
64 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-14491
65 [ 2 ] CVE-2017-14492
66 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-14492
67 [ 3 ] CVE-2017-14493
68 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-14493
69 [ 4 ] CVE-2017-14494
70 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-14494
71 [ 5 ] CVE-2017-14495
72 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-14495
73 [ 6 ] CVE-2017-14496
74 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-14496
75
76 Availability
77 ============
78
79 This GLSA and any updates to it are available for viewing at
80 the Gentoo Security Website:
81
82 https://security.gentoo.org/glsa/201710-27
83
84 Concerns?
85 =========
86
87 Security is a primary focus of Gentoo Linux and ensuring the
88 confidentiality and security of our users' machines is of utmost
89 importance to us. Any security concerns should be addressed to
90 security@g.o or alternatively, you may file a bug at
91 https://bugs.gentoo.org.
92
93 License
94 =======
95
96 Copyright 2017 Gentoo Foundation, Inc; referenced text
97 belongs to its owner(s).
98
99 The contents of this document are licensed under the
100 Creative Commons - Attribution / Share Alike license.
101
102 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature