CVE-2024-2169

Public on 2024-03-19
Modified on 2024-04-16
Description
Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.
Severity
Medium severity
Medium
CVSS v3 Base Score
5.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 bind Not Affected
Amazon Linux 2 - Core bind Not Affected
Amazon Linux 2023 bind Not Affected
Amazon Linux 1 dnsmasq Not Affected
Amazon Linux 2 - Core dnsmasq Not Affected
Amazon Linux 2 - Dnsmasq Extra dnsmasq Not Affected
Amazon Linux 2 - Dnsmasq2.85 Extra dnsmasq Not Affected
Amazon Linux 2023 dnsmasq Not Affected
Amazon Linux 1 ntp Not Affected
Amazon Linux 2 - Core ntp Not Affected
Amazon Linux 1 tftp Not Affected
Amazon Linux 2 - Core tftp Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H