First published: Mon Jul 28 2008(Updated: )
dnsmasq 2.43 allows remote attackers to cause a denial of service (daemon crash) by (1) sending a DHCPINFORM while lacking a DHCP lease, or (2) attempting to renew a nonexistent DHCP lease for an invalid subnet as an "unknown client," a different vulnerability than CVE-2008-3214.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dnsmasq | =2.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3350 is categorized as a denial of service vulnerability that can crash the dnsmasq daemon.
To remediate CVE-2008-3350, upgrade dnsmasq to the latest version beyond 2.43.
CVE-2008-3350 affects dnsmasq version 2.43 specifically.
Yes, CVE-2008-3350 can be exploited by remote attackers under certain conditions related to DHCP requests.
The attack vectors for CVE-2008-3350 include sending a DHCPINFORM without a lease or renewing a nonexistent DHCP lease.