RULE(RULE ID:105228)

Rule General Information
Release Date: 2017-10-10
Rule Name: Dnsmasq Lack of Free Denial of Service Vulnerability (CVE-2017-14495)
Severity:
CVE ID:
Rule Protection Details
Description: Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Other Unix, FreeBSD, Linux
Reference: CVE-2017-14495
ExploitDB:42945
Solutions
The vendor has issued a fix (2.78). The vendor advisory is available at http://www.thekelleys.org.uk/dnsmasq/CHANGELOG