Table of Contents

CVE 2017-14494

'dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.'

ClearCenter response

Short response

This issue was resolved in a backported fix. Current up to date versions not affected.

Long response

This issue was resolved in ddnsmasq-2.76-2 for ClearOS 7.x. Systems with this version of dnsmasq or higher are not affected by this issue. ClearOS 6 systems are not affected by this vulnerability.

Resolution

To validate that you are running dnsmasq-2.76-2 or higher by issuing the following command:

rpm -qi dnsmasq

If you are running a lesser version than dnsmasq-2.76-2 on ClearOS 7, please update your system by running:

yum update

search?q=clearos%2C%20clearos%20content%2C%20CVE%2C%20CVE2017%2C%20maintainer_dloper&btnI=lucky