CVE-2015-3294: Medium severity dnsmasq vulnerability
The tcprequest function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setupreply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3294?
CVE-2015-3294 has been classified with a moderate severity level due to its potential for causing denial of service through process memory exploitation.
How do I fix CVE-2015-3294?
To fix CVE-2015-3294, you should update Dnsmasq to version 2.73rc4 or later, as this version addresses the vulnerability.
Which versions of Dnsmasq are affected by CVE-2015-3294?
CVE-2015-3294 affects Dnsmasq versions up to and including 2.73rc3.
Can CVE-2015-3294 be exploited remotely?
Yes, CVE-2015-3294 can be exploited by remote attackers through the submission of malformed DNS requests.
What are the consequences of an exploit of CVE-2015-3294?
An exploit of CVE-2015-3294 can lead to an out-of-bounds read and cause the Dnsmasq service to crash, resulting in denial of service.