CVE-2017-13704 REJECTED

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

EPSS 79.32% · 99.1th percentile

Risk Scores

EPSS Score
79.32%
99.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSdnsmasq0, 2.66-4ubuntu1, 2.67-1
Ubuntu:16.04:LTSdnsmasq0, 2.75-1, 2.75-1ubuntu0.16.04.1

Timeline

References

Open in Interactive Console →