Please backport CVE-2017-13704 fix from dnsmasq 2.78 to 2.76 for Newton cloud-archive

Bug #1741271 reported by James Denton
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu Cloud Archive
Fix Released
High
Unassigned
Newton
Invalid
Undecided
Unassigned
Ocata
Invalid
Undecided
Unassigned

Bug Description

CVE-2017-13704 was addressed in dnsmasq-2.78, but has not been backported to a dnsmasq release available to the cloud archive(s). Would it be possible to address this, especially for >= Newton?

CVE References

James Page (james-page)
Changed in cloud-archive:
status: New → Triaged
importance: Undecided → High
information type: Public → Public Security
Changed in cloud-archive:
status: Triaged → Fix Released
Revision history for this message
Corey Bryant (corey.bryant) wrote :

Hi James,

It appears CVE-2017-13704 is a regression that was introduced in dnsmasq 2.77. This is noted in a few places, such as:

https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-13704.html
https://bugzilla.redhat.com/show_bug.cgi?id=1495510

For now I'm going to close this as invalid, however if you find that this issue does affect versions prior to 2.77, please re-open this bug and set the status to New.

Thanks,
Corey

Revision history for this message
James Denton (james-denton) wrote :

Thanks Corey. Sorry for the goose chase.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.