Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 characters.
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "dnsmasq",
"binary_version": "2.68-1ubuntu0.2+esm6"
},
{
"binary_name": "dnsmasq-base",
"binary_version": "2.68-1ubuntu0.2+esm6"
},
{
"binary_name": "dnsmasq-utils",
"binary_version": "2.68-1ubuntu0.2+esm6"
}
],
"priority_reason": "Denial of service in command line tool"
}
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "dnsmasq",
"binary_version": "2.90-0ubuntu0.18.04.1+esm1"
},
{
"binary_name": "dnsmasq-base",
"binary_version": "2.90-0ubuntu0.18.04.1+esm1"
},
{
"binary_name": "dnsmasq-base-lua",
"binary_version": "2.90-0ubuntu0.18.04.1+esm1"
},
{
"binary_name": "dnsmasq-utils",
"binary_version": "2.90-0ubuntu0.18.04.1+esm1"
}
],
"priority_reason": "Denial of service in command line tool"
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "dnsmasq",
"binary_version": "2.90-0ubuntu0.22.04.1"
},
{
"binary_name": "dnsmasq-base",
"binary_version": "2.90-0ubuntu0.22.04.1"
},
{
"binary_name": "dnsmasq-base-lua",
"binary_version": "2.90-0ubuntu0.22.04.1"
},
{
"binary_name": "dnsmasq-utils",
"binary_version": "2.90-0ubuntu0.22.04.1"
}
],
"priority_reason": "Denial of service in command line tool"
}