CVE-2019-14834 is a memory leak vulnerability in dnsmasq versions prior to 2.81, affecting products like fedoraproject dnsmasq and thekelleys dnsmasq. This low-severity flaw (CVSS 3.7) allows remote attackers to cause a denial of service through memory exhaustion via crafted DHCP responses, though it requires high attack complexity. There is no evidence of active exploitation, no publicly available exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. The vulnerability is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.81CPE matchmatch criteria | cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-14834
Aug 11, 2020A vulnerability was found in dnsmasq before version 2.81 where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
Jan 14, 2020dnsmasq: memory leak in the create_helper() function in /src/helper.c
Oct 23, 2019