• CVE-2017-14491—A DNS-based remote code execution vulnerability in Dnsmasq versions before 2.76 is marked as the most severe that allows for unrestricted heap overflows, affecting both directly exposed and internal network setups. • CVE-2017-14492—Another remote code execution vulnerability due to a DHCP-based heap overflow issue. • CVE-2017-14493—Another noteworthy DHCP-based remote code execution bug caused by a stack buffer overflow. According to Google, this flaw is trivial to exploit if it's used in conjunction with the flaw (CVE-2017-14494) mentioned below. • CVE-2017-14494—An information leak in DHCP which can be combined with CVE-2017-14493 to allow attackers bypass ASLR security mechanism and execute arbitrary code on a target system. • CVE-2017-14495—A flaw in Dnsmasq which can be exploited to launch a denial of service (DoS) attack by exhausting memory via DNS. The flaw impacts dnsmasq only if one of these options is used: --add-mac, --add-cpe-id or --add-subnet. • CVE-2017-14496—Google's Android operating system is specifically affected by this DoS issue which can be exploited by a local hacker or one who is tethered directly to the device. However, Google pointed out the service itself is sandboxed, so the risk to Android users is reduced. • CVE-2017-14497—Another DoS issue wherein a large DNS query can crash the software.
FWIW I have sent an upgrade for meta-networking master to 2.78 (in master-next, not yet merged into master): https://patchwork.openembedded.org/patch/144640/ That version includes fixes for the following CVEs (from dnsmasq's own changelog): CVE-2017-13704 CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 Are you sure you have the CVE numbers correct? CVE-2017-14497 appears to be for the kernel and not dnsmasq.
To update the status - my patch was merged into master (and rocko when it branched), but we are still missing fixes for pyro and possibly morty / earlier. I am not currently working on those - is anyone else?
backport to pyro and morty stable/*. pending merge to real branch
need to build, test and merge to stable branches
Joe, can you build, test and if all goes well, send backport patches for pyro and morty to help out Armin.
Looking into using 2.78 -> 2.76 backport. CVE-2017-13704 is not relevant to 2.76 and is fixed in 2.78.
Add a comment to see if Joe gets an email.
Patch sent for meta-networking/morty.
patches submitted to maintainer for inclusion in stable branches.
Still marked as new in patchworks: https://patchwork.openembedded.org/patch/150498/
in morty proper. http://cgit.openembedded.org/meta-openembedded/commit/?h=morty&id=997caf9146cd3797cd054e2adebd1fbb4df91911