CVE-2017-14491 is a critical heap-based buffer overflow vulnerability in dnsmasq versions prior to 2.78, affecting a wide range of products including those from Arista, Huawei, Microsoft, and various Linux distributions. This flaw allows remote attackers to cause a denial of service or execute arbitrary code via a crafted DNS response. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, it presents a significant risk due to its network-based attack vector and low attack complexity. While not on CISA's KEV catalog, public exploit code exists (EDB-42941), and it has garnered substantial community discussion and media coverage, indicating widespread awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.77CPE matchmatch criteria | cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.