dnsmasq 2.43 allows remote attackers to cause a denial of service (daemon crash) by (1) sending a DHCPINFORM while lacking a DHCP lease, or (2) attempting to renew a nonexistent DHCP lease for an invalid subnet as an "unknown client," a different vulnerability than CVE-2008-3214.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/43960 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43957 | vdb entry |
http://article.gmane.org/gmane.network.dns.dnsmasq.general/2189 | mailing list patch |
http://www.thekelleys.org.uk/dnsmasq/CHANGELOG | |
http://secunia.com/advisories/31197 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2008/2166 | vdb entry |