Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies...
Vulnerability Description
Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-3411
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:072
- http://rhn.redhat.com/errata/RHSA-2013-0276.html
- http://www.openwall.com/lists/oss-security/2012/07/12/5
- http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commitdiff%3Bh=2f38141f434e23292f84cefc33e8de76fb856147
- https://bugzilla.redhat.com/show_bug.cgi?id=833033
- http://rhn.redhat.com/errata/RHSA-2013-0579.html
- http://www.thekelleys.org.uk/dnsmasq/CHANGELOG
- http://www.securityfocus.com/bid/54353
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683372
- http://rhn.redhat.com/errata/RHSA-2013-0277.html
- http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commitdiff%3Bh=54dd393f3938fc0c19088fbd319b95e37d81a2b0
More from thekelleys
View All →Affected Vendor
thekelleys
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.