<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>12178</bug_id>
          
          <creation_ts>2017-10-04 06:21:21 +0000</creation_ts>
          <short_desc>Dnsmasq: multiple CVEs in Widely Used Dnsmasq Network Software ** Severity urgent **</short_desc>
          <delta_ts>2018-06-14 15:01:44 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>Security - Recipe Upgrade</product>
          <component>security</component>
          <version>unspecified</version>
          <rep_platform>Other</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>2.3.4</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sona Sarmadi">sona.sarmadi</reporter>
          <assigned_to name="Joe Slater">joe.slater</assigned_to>
          <cc>akuster</cc>
    
    <cc>bluelightning</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>stephano</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>77329</commentid>
    <comment_count>0</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2017-10-04 06:21:21 +0000</bug_when>
    <thetext>•	CVE-2017-14491—A DNS-based remote code execution vulnerability in Dnsmasq versions before 2.76 is marked as the most severe that allows for unrestricted heap overflows, affecting both directly exposed and internal network setups.
•	CVE-2017-14492—Another remote code execution vulnerability due to a DHCP-based heap overflow issue.
•	CVE-2017-14493—Another noteworthy DHCP-based remote code execution bug caused by a stack buffer overflow. According to Google, this flaw is trivial to exploit if it&apos;s used in conjunction with the flaw (CVE-2017-14494) mentioned below.
•	CVE-2017-14494—An information leak in DHCP which can be combined with CVE-2017-14493 to allow attackers bypass ASLR security mechanism and execute arbitrary code on a target system.
•	CVE-2017-14495—A flaw in Dnsmasq which can be exploited to launch a denial of service (DoS) attack by exhausting memory via DNS. The flaw impacts dnsmasq only if one of these options is used: --add-mac, --add-cpe-id or --add-subnet.
•	CVE-2017-14496—Google&apos;s Android operating system is specifically affected by this DoS issue which can be exploited by a local hacker or one who is tethered directly to the device. However, Google pointed out the service itself is sandboxed, so the risk to Android users is reduced.
•	CVE-2017-14497—Another DoS issue wherein a large DNS query can crash the software.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77409</commentid>
    <comment_count>1</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2017-10-06 03:12:19 +0000</bug_when>
    <thetext>FWIW I have sent an upgrade for meta-networking master to 2.78 (in master-next, not yet merged into master):

  https://patchwork.openembedded.org/patch/144640/

That version includes fixes for the following CVEs (from dnsmasq&apos;s own changelog):

  CVE-2017-13704
  CVE-2017-14491
  CVE-2017-14492
  CVE-2017-14493
  CVE-2017-14494
  CVE-2017-14495
  CVE-2017-14496

Are you sure you have the CVE numbers correct? CVE-2017-14497 appears to be for the kernel and not dnsmasq.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78414</commentid>
    <comment_count>2</comment_count>
    <who name="Paul Eggleton">bluelightning</who>
    <bug_when>2017-11-29 22:13:13 +0000</bug_when>
    <thetext>To update the status - my patch was merged into master (and rocko when it branched), but we are still missing fixes for pyro and possibly morty / earlier. I am not currently working on those - is anyone else?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>79416</commentid>
    <comment_count>3</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2018-02-11 23:50:48 +0000</bug_when>
    <thetext>backport to pyro and morty stable/*. pending merge to real branch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>79622</commentid>
    <comment_count>4</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2018-02-28 04:55:23 +0000</bug_when>
    <thetext>need to build, test and merge to stable branches</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80417</commentid>
    <comment_count>5</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2018-04-26 08:10:00 +0000</bug_when>
    <thetext>Joe, can you build, test and if all goes well, send backport patches for pyro and morty to help out Armin.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80487</commentid>
    <comment_count>6</comment_count>
    <who name="Joe Slater">joe.slater</who>
    <bug_when>2018-05-03 14:03:42 +0000</bug_when>
    <thetext>Looking into using 2.78 -&gt; 2.76 backport. CVE-2017-13704 is not relevant to 2.76 and is fixed in 2.78.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80488</commentid>
    <comment_count>7</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2018-05-03 15:55:07 +0000</bug_when>
    <thetext>Add a comment to see if Joe gets an email.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80494</commentid>
    <comment_count>8</comment_count>
    <who name="Joe Slater">joe.slater</who>
    <bug_when>2018-05-04 15:22:53 +0000</bug_when>
    <thetext>Patch sent for meta-networking/morty.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80707</commentid>
    <comment_count>9</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2018-06-04 15:45:19 +0000</bug_when>
    <thetext>patches submitted to maintainer for inclusion in stable branches.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80731</commentid>
    <comment_count>10</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2018-06-07 15:11:48 +0000</bug_when>
    <thetext>Still marked as new in patchworks:
   https://patchwork.openembedded.org/patch/150498/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80790</commentid>
    <comment_count>11</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2018-06-14 15:01:44 +0000</bug_when>
    <thetext>in morty proper.

http://cgit.openembedded.org/meta-openembedded/commit/?h=morty&amp;id=997caf9146cd3797cd054e2adebd1fbb4df91911</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>