CVE-2015-8899: Input Validation
Published Jun 30, 2016
·Updated
Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.
Affected Software
3 affected components
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
thekelleys dnsmasq<=2.75
Event History
Jun 30, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8899?
CVE-2015-8899 has a severity rating of medium due to its ability to cause denial of service.
2
How do I fix CVE-2015-8899?
To fix CVE-2015-8899, upgrade dnsmasq to version 2.76 or later.
3
What types of systems are affected by CVE-2015-8899?
CVE-2015-8899 affects dnsmasq versions up to 2.75 and Ubuntu Linux versions 15.10 and 16.04 LTS.
4
What impact does CVE-2015-8899 have on my system?
CVE-2015-8899 can cause your dnsmasq service to crash, resulting in a denial of service.
5
Is CVE-2015-8899 exploitable remotely?
Yes, CVE-2015-8899 can be exploited by remote servers sending specific DNS replies.