PT-2009-1002 · Dnsmasq+1 · Dnsmasq+1

Steve

·

Published

2009-08-31

·

Updated

2017-09-19

·

CVE-2009-2958

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dnsmasq versions prior to 2.50
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This can be achieved by sending a TFTP read request with a malformed blksize option. The vulnerability can be exploited when the --enable-tftp option is used.
Recommendations For versions prior to 2.50, update to version 2.50 or later to resolve the issue. As a temporary workaround, consider disabling the tftp request function or restricting the use of the TFTP service until a patch is available. Avoid using the blksize option in TFTP read requests until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00415
BDU:2015-06168
BDU:2015-08541
CVE-2009-2958
DSA-1876-1
RHSA-2009:1238
RHSA-2009_1238

Affected Products

Red Hat
Dnsmasq