5
CVSSv2

CVE-2013-0198

Published: 05/03/2013 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Dnsmasq prior to 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote malicious users to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thekelleys dnsmasq

Vendor Advisories

Debian Bug report logs - #683372 CVE-2012-3411: libvirt-controlled dnsmasq replies to DNS queries from non-virtual networks Package: dnsmasq; Maintainer for dnsmasq is Simon Kelley <simon@thekelleysorguk>; Source for dnsmasq is src:dnsmasq (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde& ...