CVE Vulnerabilities

CVE-2017-14496

Integer Underflow (Wrap or Wraparound)

Published: Oct 03, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
7.8 IMPORTANT
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V3
7.5 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the –add-mac, –add-cpe-id or –add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
Ubuntu_linuxCanonical16.04 (including)16.04 (including)
Ubuntu_linuxCanonical17.04 (including)17.04 (including)
Debian_linuxDebian7.0 (including)7.0 (including)
Debian_linuxDebian7.1 (including)7.1 (including)
Debian_linuxDebian9.0 (including)9.0 (including)
AndroidGoogle4.4.4 (including)4.4.4 (including)
AndroidGoogle5.0.2 (including)5.0.2 (including)
AndroidGoogle5.1.1 (including)5.1.1 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)
AndroidGoogle7.0 (including)7.0 (including)
AndroidGoogle7.1.1 (including)7.1.1 (including)
AndroidGoogle7.1.2 (including)7.1.2 (including)
AndroidGoogle8.0 (including)8.0 (including)
LeapNovell42.2 (including)42.2 (including)
LeapNovell42.3 (including)42.3 (including)
Enterprise_linux_desktopRedhat7.0 (including)7.0 (including)
Enterprise_linux_serverRedhat7.0 (including)7.0 (including)
Enterprise_linux_workstationRedhat7.0 (including)7.0 (including)
Red Hat Enterprise Linux 7RedHatdnsmasq-0:2.76-2.el7_4.2*
DnsmasqUbuntuesm-infra-legacy/trusty*
DnsmasqUbuntuesm-infra/xenial*
DnsmasqUbuntutrusty*
DnsmasqUbuntutrusty/esm*
DnsmasqUbuntuxenial*
DnsmasqUbuntuzesty*

References