PT-2025-43757 · Dnsmasq · Dnsmasq
Zh_Vul
·
Published
2025-10-27
·
Updated
2025-11-02
·
CVE-2025-12199
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dnsmasq versions up to 2.73rc6
Description
A flaw exists in dnsmasq that involves a null pointer dereference within the
check servers function, located in the src/network.c file of the Config File Handler component. This issue can be triggered through local exploitation. The exploit for this issue has been publicly released, and attempts to notify the vendor were unsuccessful.Recommendations
Versions prior to 2.73rc6 should be used.
Exploit
Fix
NULL Pointer Dereference
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dnsmasq