RULE(RULE ID:105226)

Rule General Information
Release Date: 2017-10-10
Rule Name: Dnsmasq Integer Buffer Overflow Vulnerability (CVE-2017-14496)
Severity:
CVE ID:
Rule Protection Details
Description: Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Other Unix, FreeBSD, Linux
Reference: CVE-2017-14496
ExploitDB:42946
Solutions
The vendor has issued a fix (2.78). The vendor advisory is available at http://www.thekelleys.org.uk/dnsmasq/CHANGELOG