RHSA-2009:1238: Important: dnsmasq security update
Dnsmasq is a lightweight and easy to configure DNS forwarder and DHCPserver.Core Security Technologies discovered a heap overflow flaw in dnsmasq whenthe TFTP service is enabled (the "--enable-tftp" command line option, or byenabling "enable-tftp" in "/etc/dnsmasq.conf"). If the configured tftp-rootis sufficiently long, and a remote user sends a request that sends a longfile name, dnsmasq could crash or, possibly, execute arbitrary code withthe privileges of the dnsmasq service (usually the unprivileged "nobody"user). (CVE-2009-2957)A NULL pointer dereference flaw was discovered in dnsmasq when the TFTPservice is enabled. This flaw could allow a malicious TFTP client to crashthe dnsmasq service. (CVE-2009-2958)Note: The default tftp-root is "/var/ftpd", which is short enough to makeit difficult to exploit the CVE-2009-2957 issue; if a longer directory nameis used, arbitrary code execution may be possible. As well, the dnsmasqpackage distributed by Red Hat does not have TFTP support enabled bydefault.All users of dnsmasq should upgrade to this updated package, which containsa backported patch to correct these issues. After installing the updatedpackage, the dnsmasq service must be restarted for the update to takeeffect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1238?
The severity of RHSA-2009:1238 is classified as important.
How do I fix RHSA-2009:1238?
To fix RHSA-2009:1238, upgrade dnsmasq to version 2.45-1.1.el5_3 or later.
What is the vulnerability description of RHSA-2009:1238?
RHSA-2009:1238 describes a heap overflow flaw in dnsmasq when the TFTP service is enabled.
Which versions of dnsmasq are affected by RHSA-2009:1238?
RHSA-2009:1238 affects dnsmasq versions earlier than 2.45-1.1.el5_3.
What should I do if I cannot upgrade dnsmasq regarding RHSA-2009:1238?
If unable to upgrade dnsmasq, consider disabling the TFTP service to mitigate the risk described in RHSA-2009:1238.