Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities.
CVSS
No CVSS.
References
No reference.
Configurations
No configuration.
History
03 Nov 2025, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | (en) Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities. | |
| CWE | CWE-119 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
03 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A vulnerability has been found in dnsmasq up to 2.73rc6. Affected is the function parse_hex of the file src/util.c of the component Config File Handler. The manipulation of the argument i leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. This attack requires manipulating config files which might not be a realistic scenario in many cases. The vendor was contacted early about this disclosure but did not respond in any way. |
01 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://www.openwall.com/lists/oss-security/2025/10/27/1 - |
28 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
28 Oct 2025, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
28 Oct 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 Oct 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 01:15
Updated : 2025-11-03 23:17
NVD link : CVE-2025-12198
Mitre link : CVE-2025-12198
CVE.ORG link : CVE-2025-12198
JSON object : View
Products Affected
No product.
CWE
No CWE.
