CVE-2008-3214

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK response from the daemon.

References

http://freshmeat.net/projects/dnsmasq/?branch_id=1991&release_id=217681

http://www.openwall.com/lists/oss-security/2008/06/30/7

http://www.openwall.com/lists/oss-security/2008/07/01/8

http://www.openwall.com/lists/oss-security/2008/07/02/4

http://www.openwall.com/lists/oss-security/2008/07/03/4

http://www.openwall.com/lists/oss-security/2008/07/08/8

http://www.openwall.com/lists/oss-security/2008/07/12/3

http://www.thekelleys.org.uk/dnsmasq/CHANGELOG

https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/47438

https://exchange.xforce.ibmcloud.com/vulnerabilities/43929

Details

Source: MITRE

Published: 2008-07-18

Updated: 2017-08-08

Type: CWE-20

Risk Information

CVSS v2

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:thekelleys:dnsmasq:2.25:*:*:*:*:*:*:*

Tenable Plugins

View all (1 total)

IDNameProductFamilySeverity
106137dnsmasq 2.25 DHCP Request Denial of Service (CVE-2008-3214)NessusDNS
medium