CVE-2019-14834
LOW EPSS 83.8%
Published Jan 7, 20206y ago · Modified Jun 17, 20262w ago
3.7 CVSS 3.1
Published Jan 7, 2020 6y ago
Last Modified Jun 17, 2026 2w ago
Description
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability Low
Threat Intelligence
EPSS Exploit Probability
83.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-770
Affected Products 2
| Vendor | Product | Version | Range |
|---|---|---|---|
| thekelleys | dnsmasq | * | <2.81 |
| fedoraproject | fedora | 31 | any |
References 3
- thekelleys.org.uk http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=69bc94779c2f035a9fffdb5327a54c3aeca73ed5
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14834
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JU474LT66BHNVFG5C4GEV3VTZNAEJ3BS/
Remediation
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14834