Vulnerability Name: | CVE-2008-3214 (CCN-43929) | ||||||||
Assigned: | 2008-06-30 | ||||||||
Published: | 2008-06-30 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK response from the daemon. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 6.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-3214 Source: CONFIRM Type: UNKNOWN http://freshmeat.net/projects/dnsmasq/?branch_id=1991&release_id=217681 Source: CCN Type: oss-security Mailing List, Mon, 30 Jun 2008 17:23:19 -0400 CVE request for dnsmasq DoS Source: MLIST Type: UNKNOWN [oss-security] 20080630 CVE request for dnsmasq DoS Source: MLIST Type: UNKNOWN [oss-security] 20080701 Re: CVE request for dnsmasq DoS Source: MLIST Type: UNKNOWN [oss-security] 20080702 Re: CVE request for dnsmasq DoS Source: MLIST Type: UNKNOWN [oss-security] 20080703 Re: CVE request for dnsmasq DoS Source: MLIST Type: UNKNOWN [oss-security] 20080708 Re: CVE request for dnsmasq DoS Source: MLIST Type: Exploit [oss-security] 20080712 Re: CVE request for dnsmasq DoS Source: CCN Type: OSVDB ID: 47509 Dnsmasq Nonexistent DHCP Lease Renewal Request Remote DoS Source: CCN Type: OSVDB ID: 49083 Dnsmasq Crafted DHCPINFORM Request Remote DoS Source: CCN Type: OSVDB ID: 49084 Dnsmasq Netlink Code Unspecified DoS Source: CONFIRM Type: UNKNOWN http://www.thekelleys.org.uk/dnsmasq/CHANGELOG Source: CCN Type: Dnsmasq Web page Dnsmasq Source: CCN Type: Launchpad Bug #47438 Dnsmasq crashes when renewing non-existent lease Source: CONFIRM Type: Exploit https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/47438 Source: XF Type: UNKNOWN dnsmasq-multiple-dos(43929) Source: XF Type: UNKNOWN dnsmasq-multiple-dos(43929) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |