peter bassill · operator
$ cve CVE-2017-14491 JSON

CVE-2017-14491 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 84.9% (pctl 100)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS84.93% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2017-10-04
Last modified2026-06-17

Affected (29)

VendorProduct
aristaeos
arubanetworksarubaos
canonicalubuntu linux
debiandebian linux
huaweihonor v9 play
huaweihonor v9 play firmware
microsoftwindows
nvidiageforce experience
nvidiajetson tk1
nvidiajetson tx1
nvidialinux for tegra
opensuseleap
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
siemensruggedcom rm1224
siemensruggedcom rm1224 firmware
siemensscalance m-800
siemensscalance m-800 firmware
siemensscalance s615
siemensscalance s615 firmware
siemensscalance w1750d
siemensscalance w1750d firmware
suselinux enterprise debuginfo
suselinux enterprise point of sale
suselinux enterprise server
synologydiskstation manager
synologyrouter manager
thekelleysdnsmasq

Public exploits

SourceTitleDate
exploit-dbDnsmasq < 2.78 - 2-byte Heap Overflow2017-10-02

References

→ the Explorer  ·  watch your stack  ·  NVD