OSSN-0082: Heap and Stack based buffer overflows in dnsmasq prior to version 2.78

Summary

A series of heap and stack based buffer overflows have been discovered in versions of dnsmasq prior to release 2.78.

Affected Services / Software

Any neutron based OpenStack deployment on a version of dnsmasq prior to 2.78.

Discussion

The following attack vectors have been assigned the following CVE numbers:

  • CVE-2017-14491

  • CVE-2017-14492

  • CVE-2017-14493

  • CVE-2017-14494

  • CVE-2017-14495

  • CVE-2017-14496

  • CVE-2017-13704

Each of these CVEs exposes a neutron based OpenStack deployment to various attacks such as leakage of sensitive memory information or causing a denial of service. Nodes are exposed to this risk by the crafting of various nefarious DNS or DHCP requests.

Contacts / References

Author: Luke Hinds <lhinds@redhat.com>