CVE-2013-0198

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
05/03/2013
Last modified:
11/04/2025

Description

Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:* 2.65 (including)