CVE-2009-2957
Thekelleys Dnsmasq < 2.49 - Memory Corruption
Title source: ruleDescription
Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.
Exploits (1)
References (9)
Scores
EPSS
0.0853
EPSS Percentile
92.4%
Details
CWE
CWE-119
Status
published
Products (50)
thekelleys/dnsmasq
0.4
thekelleys/dnsmasq
0.5
thekelleys/dnsmasq
0.6
thekelleys/dnsmasq
0.7
thekelleys/dnsmasq
0.95
thekelleys/dnsmasq
0.96
thekelleys/dnsmasq
0.98
thekelleys/dnsmasq
0.992
thekelleys/dnsmasq
0.996
thekelleys/dnsmasq
1.0
... and 40 more
Published
Sep 02, 2009
Tracked Since
Feb 18, 2026