CVE-2008-3350

MEDIUM

Description

dnsmasq 2.43 allows remote attackers to cause a denial of service (daemon crash) by (1) sending a DHCPINFORM while lacking a DHCP lease, or (2) attempting to renew a nonexistent DHCP lease for an invalid subnet as an "unknown client," a different vulnerability than CVE-2008-3214.

References

http://article.gmane.org/gmane.network.dns.dnsmasq.general/2189

http://secunia.com/advisories/31197

http://www.thekelleys.org.uk/dnsmasq/CHANGELOG

http://www.vupen.com/english/advisories/2008/2166

https://exchange.xforce.ibmcloud.com/vulnerabilities/43957

https://exchange.xforce.ibmcloud.com/vulnerabilities/43960

Details

Source: MITRE

Published: 2008-07-28

Updated: 2017-08-08

Risk Information

CVSS v2.0

Base Score: 5

Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM