CVE-2008-3214
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
18/07/2008
Last modified:
09/04/2025
Description
dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK response from the daemon.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:thekelleys:dnsmasq:2.25:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://freshmeat.net/projects/dnsmasq/?branch_id=1991&release_id=217681
- http://www.openwall.com/lists/oss-security/2008/06/30/7
- http://www.openwall.com/lists/oss-security/2008/07/01/8
- http://www.openwall.com/lists/oss-security/2008/07/02/4
- http://www.openwall.com/lists/oss-security/2008/07/03/4
- http://www.openwall.com/lists/oss-security/2008/07/08/8
- http://www.openwall.com/lists/oss-security/2008/07/12/3
- http://www.thekelleys.org.uk/dnsmasq/CHANGELOG
- https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/47438
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43929
- http://freshmeat.net/projects/dnsmasq/?branch_id=1991&release_id=217681
- http://www.openwall.com/lists/oss-security/2008/06/30/7
- http://www.openwall.com/lists/oss-security/2008/07/01/8
- http://www.openwall.com/lists/oss-security/2008/07/02/4
- http://www.openwall.com/lists/oss-security/2008/07/03/4
- http://www.openwall.com/lists/oss-security/2008/07/08/8
- http://www.openwall.com/lists/oss-security/2008/07/12/3
- http://www.thekelleys.org.uk/dnsmasq/CHANGELOG
- https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/47438
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43929