CVE Vulnerabilities

CVE-2009-2958

Published: Sep 02, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The tftp_request function in tftp.c in dnsmasq before 2.50, when –enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.

Affected Software

NameVendorStart VersionEnd Version
DnsmasqThekelleys*2.49 (including)
DnsmasqThekelleys0.4 (including)0.4 (including)
DnsmasqThekelleys0.5 (including)0.5 (including)
DnsmasqThekelleys0.6 (including)0.6 (including)
DnsmasqThekelleys0.7 (including)0.7 (including)
DnsmasqThekelleys0.95 (including)0.95 (including)
DnsmasqThekelleys0.96 (including)0.96 (including)
DnsmasqThekelleys0.98 (including)0.98 (including)
DnsmasqThekelleys0.992 (including)0.992 (including)
DnsmasqThekelleys0.996 (including)0.996 (including)
DnsmasqThekelleys1.0 (including)1.0 (including)
DnsmasqThekelleys1.2 (including)1.2 (including)
DnsmasqThekelleys1.3 (including)1.3 (including)
DnsmasqThekelleys1.4 (including)1.4 (including)
DnsmasqThekelleys1.5 (including)1.5 (including)
DnsmasqThekelleys1.6 (including)1.6 (including)
DnsmasqThekelleys1.7 (including)1.7 (including)
DnsmasqThekelleys1.8 (including)1.8 (including)
DnsmasqThekelleys1.9 (including)1.9 (including)
DnsmasqThekelleys1.10 (including)1.10 (including)
DnsmasqThekelleys1.11 (including)1.11 (including)
DnsmasqThekelleys1.12 (including)1.12 (including)
DnsmasqThekelleys1.13 (including)1.13 (including)
DnsmasqThekelleys1.14 (including)1.14 (including)
DnsmasqThekelleys1.15 (including)1.15 (including)
DnsmasqThekelleys1.16 (including)1.16 (including)
DnsmasqThekelleys1.17 (including)1.17 (including)
DnsmasqThekelleys1.18 (including)1.18 (including)
DnsmasqThekelleys2.0 (including)2.0 (including)
DnsmasqThekelleys2.1 (including)2.1 (including)
DnsmasqThekelleys2.2 (including)2.2 (including)
DnsmasqThekelleys2.3 (including)2.3 (including)
DnsmasqThekelleys2.4 (including)2.4 (including)
DnsmasqThekelleys2.5 (including)2.5 (including)
DnsmasqThekelleys2.6 (including)2.6 (including)
DnsmasqThekelleys2.7 (including)2.7 (including)
DnsmasqThekelleys2.8 (including)2.8 (including)
DnsmasqThekelleys2.9 (including)2.9 (including)
DnsmasqThekelleys2.10 (including)2.10 (including)
DnsmasqThekelleys2.11 (including)2.11 (including)
DnsmasqThekelleys2.12 (including)2.12 (including)
DnsmasqThekelleys2.13 (including)2.13 (including)
DnsmasqThekelleys2.14 (including)2.14 (including)
DnsmasqThekelleys2.15 (including)2.15 (including)
DnsmasqThekelleys2.16 (including)2.16 (including)
DnsmasqThekelleys2.17 (including)2.17 (including)
DnsmasqThekelleys2.18 (including)2.18 (including)
DnsmasqThekelleys2.19 (including)2.19 (including)
DnsmasqThekelleys2.20 (including)2.20 (including)
DnsmasqThekelleys2.21 (including)2.21 (including)
DnsmasqThekelleys2.22 (including)2.22 (including)
DnsmasqThekelleys2.23 (including)2.23 (including)
DnsmasqThekelleys2.24 (including)2.24 (including)
DnsmasqThekelleys2.25 (including)2.25 (including)
DnsmasqThekelleys2.26 (including)2.26 (including)
DnsmasqThekelleys2.27 (including)2.27 (including)
DnsmasqThekelleys2.28 (including)2.28 (including)
DnsmasqThekelleys2.29 (including)2.29 (including)
DnsmasqThekelleys2.30 (including)2.30 (including)
DnsmasqThekelleys2.31 (including)2.31 (including)
DnsmasqThekelleys2.33 (including)2.33 (including)
DnsmasqThekelleys2.34 (including)2.34 (including)
DnsmasqThekelleys2.35 (including)2.35 (including)
DnsmasqThekelleys2.36 (including)2.36 (including)
DnsmasqThekelleys2.37 (including)2.37 (including)
DnsmasqThekelleys2.38 (including)2.38 (including)
DnsmasqThekelleys2.39 (including)2.39 (including)
DnsmasqThekelleys2.40 (including)2.40 (including)
DnsmasqThekelleys2.41 (including)2.41 (including)
DnsmasqThekelleys2.42 (including)2.42 (including)
DnsmasqThekelleys2.43 (including)2.43 (including)
DnsmasqThekelleys2.44 (including)2.44 (including)
DnsmasqThekelleys2.45 (including)2.45 (including)
DnsmasqThekelleys2.46 (including)2.46 (including)
DnsmasqThekelleys2.47 (including)2.47 (including)
DnsmasqThekelleys2.48 (including)2.48 (including)
Red Hat Enterprise Linux 5RedHatdnsmasq-0:2.45-1.1.el5_3*
DnsmasqUbuntudevel*
DnsmasqUbuntuhardy*
DnsmasqUbuntuintrepid*
DnsmasqUbuntujaunty*
DnsmasqUbuntuupstream*

References