CVE-2009-2958
Thekelleys Dnsmasq < 2.49 - Resource Management Error
Title source: ruleDescription
The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Core Security · textdoswindows
https://www.exploit-db.com/exploits/9617
References (9)
Scores
EPSS
0.0113
EPSS Percentile
78.1%
Classification
CWE
CWE-399
Status
draft
Affected Products (50)
thekelleys/dnsmasq
< 2.49
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
thekelleys/dnsmasq
... and 35 more
Timeline
Published
Sep 02, 2009
Tracked Since
Feb 18, 2026