Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8899

Опубликовано: 14 нояб. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.

A NULL pointer dereference flaw was found in dmsmasq in the cache_insert() function. An attacker could exploit this flaw by locally defining an A or AAAA record in the /etc/hosts file that is not in the upstream server. When the upstream server sends a reply that the same name is empty, dmsmasq crashes (denial of service).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dnsmasqNot affected
Red Hat Enterprise Linux 6dnsmasqNot affected
Red Hat Enterprise Linux 7dnsmasqNot affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)dnsmasqNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)dnsmasqNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)dnsmasqNot affected
Red Hat OpenStack Platform 8 (Liberty)dnsmasqNot affected
Red Hat OpenStack Platform 9 (Mitaka)dnsmasqNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1343072dnsmasq: Denial-of-service when empty address from DNS overlays A record from hosts

EPSS

Процентиль: 83%
0.02415
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.

CVSS3: 7.5
nvd
около 10 лет назад

Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.

CVSS3: 7.5
debian
около 10 лет назад

Dnsmasq before 2.76 allows remote servers to cause a denial of service ...

suse-cvrf
больше 9 лет назад

Security update for dnsmasq

suse-cvrf
больше 9 лет назад

Security update for dnsmasq

EPSS

Процентиль: 83%
0.02415
Низкий

4.3 Medium

CVSS2