CVE-2009-2957

Thekelleys Dnsmasq < 2.49 - Memory Corruption

Title source: rule

Description

Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

Exploits (1)

exploitdb WRITEUP
doswindows
https://www.exploit-db.com/exploits/9617

Scores

EPSS 0.0853
EPSS Percentile 92.4%

Details

CWE
CWE-119
Status published
Products (50)
thekelleys/dnsmasq 0.4
thekelleys/dnsmasq 0.5
thekelleys/dnsmasq 0.6
thekelleys/dnsmasq 0.7
thekelleys/dnsmasq 0.95
thekelleys/dnsmasq 0.96
thekelleys/dnsmasq 0.98
thekelleys/dnsmasq 0.992
thekelleys/dnsmasq 0.996
thekelleys/dnsmasq 1.0
... and 40 more
Published Sep 02, 2009
Tracked Since Feb 18, 2026