Bug 12178 - Dnsmasq: multiple CVEs in Widely Used Dnsmasq Network Software ** Severity urgent **
Summary: Dnsmasq: multiple CVEs in Widely Used Dnsmasq Network Software ** Severity ur...
Status: RESOLVED FIXED
Alias: None
Product: Security - Recipe Upgrade
Classification: Build System, Metadata & Runtime
Component: security (show other bugs)
Version: unspecified
Hardware: Other Multiple
: Medium critical
Target Milestone: 2.3.4
Assignee: Joe Slater
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2017-10-04 06:21 UTC by Sona Sarmadi
Modified: 2018-06-14 15:01 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sona Sarmadi 2017-10-04 06:21:21 UTC
•	CVE-2017-14491—A DNS-based remote code execution vulnerability in Dnsmasq versions before 2.76 is marked as the most severe that allows for unrestricted heap overflows, affecting both directly exposed and internal network setups.
•	CVE-2017-14492—Another remote code execution vulnerability due to a DHCP-based heap overflow issue.
•	CVE-2017-14493—Another noteworthy DHCP-based remote code execution bug caused by a stack buffer overflow. According to Google, this flaw is trivial to exploit if it's used in conjunction with the flaw (CVE-2017-14494) mentioned below.
•	CVE-2017-14494—An information leak in DHCP which can be combined with CVE-2017-14493 to allow attackers bypass ASLR security mechanism and execute arbitrary code on a target system.
•	CVE-2017-14495—A flaw in Dnsmasq which can be exploited to launch a denial of service (DoS) attack by exhausting memory via DNS. The flaw impacts dnsmasq only if one of these options is used: --add-mac, --add-cpe-id or --add-subnet.
•	CVE-2017-14496—Google's Android operating system is specifically affected by this DoS issue which can be exploited by a local hacker or one who is tethered directly to the device. However, Google pointed out the service itself is sandboxed, so the risk to Android users is reduced.
•	CVE-2017-14497—Another DoS issue wherein a large DNS query can crash the software.
Comment 1 Paul Eggleton 2017-10-06 03:12:19 UTC
FWIW I have sent an upgrade for meta-networking master to 2.78 (in master-next, not yet merged into master):

  https://patchwork.openembedded.org/patch/144640/

That version includes fixes for the following CVEs (from dnsmasq's own changelog):

  CVE-2017-13704
  CVE-2017-14491
  CVE-2017-14492
  CVE-2017-14493
  CVE-2017-14494
  CVE-2017-14495
  CVE-2017-14496

Are you sure you have the CVE numbers correct? CVE-2017-14497 appears to be for the kernel and not dnsmasq.
Comment 2 Paul Eggleton 2017-11-29 22:13:13 UTC
To update the status - my patch was merged into master (and rocko when it branched), but we are still missing fixes for pyro and possibly morty / earlier. I am not currently working on those - is anyone else?
Comment 3 Armin Kuster 2018-02-11 23:50:48 UTC
backport to pyro and morty stable/*. pending merge to real branch
Comment 4 Armin Kuster 2018-02-28 04:55:23 UTC
need to build, test and merge to stable branches
Comment 5 Randy MacLeod 2018-04-26 08:10:00 UTC
Joe, can you build, test and if all goes well, send backport patches for pyro and morty to help out Armin.
Comment 6 Joe Slater 2018-05-03 14:03:42 UTC
Looking into using 2.78 -> 2.76 backport. CVE-2017-13704 is not relevant to 2.76 and is fixed in 2.78.
Comment 7 Randy MacLeod 2018-05-03 15:55:07 UTC
Add a comment to see if Joe gets an email.
Comment 8 Joe Slater 2018-05-04 15:22:53 UTC
Patch sent for meta-networking/morty.
Comment 9 Armin Kuster 2018-06-04 15:45:19 UTC
patches submitted to maintainer for inclusion in stable branches.
Comment 10 Randy MacLeod 2018-06-07 15:11:48 UTC
Still marked as new in patchworks:
   https://patchwork.openembedded.org/patch/150498/