RULE(RULE ID:105227)

Rule General Information
Release Date: 2017-10-06
Rule Name: Dnsmasq 2-byte Heap-Based Buffer Overflow Vulnerability (CVE-2017-14491)
Severity:
CVE ID:
Rule Protection Details
Description: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Other Unix, FreeBSD, Linux
Reference: CVE-2017-14491
ExploitDB:42941
Solutions
The vendor has issued a fix (2.78). The vendor advisory is available at http://www.thekelleys.org.uk/dnsmasq/CHANGELOG