CVE-2009-2958: Null Pointer Dereference
Published Aug 31, 2009
·Updated
The tftprequest function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.
Affected Software
77 affected componentsFixes available
redhat/dnsmasq<0:2.45-1.1.el5_3
0:2.45-1.1.el5_3
thekelleys dnsmasq<=2.49
thekelleys dnsmasq=0.4
thekelleys dnsmasq=0.5
thekelleys dnsmasq=0.6
thekelleys dnsmasq=0.7
thekelleys dnsmasq=0.95
thekelleys dnsmasq=0.96
thekelleys dnsmasq=0.98
thekelleys dnsmasq=0.992
thekelleys dnsmasq=0.996
thekelleys dnsmasq=1.0
thekelleys dnsmasq=1.2
thekelleys dnsmasq=1.3
thekelleys dnsmasq=1.4
thekelleys dnsmasq=1.5
thekelleys dnsmasq=1.6
thekelleys dnsmasq=1.7
thekelleys dnsmasq=1.8
thekelleys dnsmasq=1.9
thekelleys dnsmasq=1.10
thekelleys dnsmasq=1.11
thekelleys dnsmasq=1.12
thekelleys dnsmasq=1.13
thekelleys dnsmasq=1.14
thekelleys dnsmasq=1.15
thekelleys dnsmasq=1.16
thekelleys dnsmasq=1.17
thekelleys dnsmasq=1.18
thekelleys dnsmasq=2.0
thekelleys dnsmasq=2.1
thekelleys dnsmasq=2.2
thekelleys dnsmasq=2.3
thekelleys dnsmasq=2.4
thekelleys dnsmasq=2.5
thekelleys dnsmasq=2.6
thekelleys dnsmasq=2.7
thekelleys dnsmasq=2.8
thekelleys dnsmasq=2.9
thekelleys dnsmasq=2.10
thekelleys dnsmasq=2.11
thekelleys dnsmasq=2.12
thekelleys dnsmasq=2.13
thekelleys dnsmasq=2.14
thekelleys dnsmasq=2.15
thekelleys dnsmasq=2.16
thekelleys dnsmasq=2.17
thekelleys dnsmasq=2.18
thekelleys dnsmasq=2.19
thekelleys dnsmasq=2.20
thekelleys dnsmasq=2.21
thekelleys dnsmasq=2.22
thekelleys dnsmasq=2.23
thekelleys dnsmasq=2.24
thekelleys dnsmasq=2.25
thekelleys dnsmasq=2.26
thekelleys dnsmasq=2.27
thekelleys dnsmasq=2.28
thekelleys dnsmasq=2.29
thekelleys dnsmasq=2.30
thekelleys dnsmasq=2.31
thekelleys dnsmasq=2.33
thekelleys dnsmasq=2.34
thekelleys dnsmasq=2.35
thekelleys dnsmasq=2.36
thekelleys dnsmasq=2.37
thekelleys dnsmasq=2.38
thekelleys dnsmasq=2.39
thekelleys dnsmasq=2.40
thekelleys dnsmasq=2.41
thekelleys dnsmasq=2.42
thekelleys dnsmasq=2.43
thekelleys dnsmasq=2.44
thekelleys dnsmasq=2.45
thekelleys dnsmasq=2.46
thekelleys dnsmasq=2.47
thekelleys dnsmasq=2.48
Event History
Aug 31, 2009
CVE Published
via Red Hat·12:00 AM
Sep 2, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2958?
CVE-2009-2958 is classified as a denial of service vulnerability due to a NULL pointer dereference in dnsmasq.
2
How do I fix CVE-2009-2958?
To fix CVE-2009-2958, upgrade dnsmasq to version 2.50 or later.
3
Which versions of dnsmasq are affected by CVE-2009-2958?
Affected versions of dnsmasq include all versions before 2.50, such as 0.4 up to 2.49.
4
What type of attacks can exploit CVE-2009-2958?
CVE-2009-2958 can be exploited by remote attackers sending a malformed TFTP RRQ request.
5
What impact does CVE-2009-2958 have on a system?
The impact of CVE-2009-2958 is a crash of the dnsmasq daemon, leading to a denial of service.