CVE-2009-2958

Thekelleys Dnsmasq < 2.49 - Resource Management Error

Title source: rule

Description

The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Core Security · textdoswindows
https://www.exploit-db.com/exploits/9617

Scores

EPSS 0.0113
EPSS Percentile 78.1%

Classification

CWE
CWE-399
Status draft

Affected Products (50)

thekelleys/dnsmasq < 2.49
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
... and 35 more

Timeline

Published Sep 02, 2009
Tracked Since Feb 18, 2026