DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in answerrequest (called from FuzzAnswerTheRequest and fuzzrfc1035.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge."
DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in printmac (called from logpacket and dhcpreply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge."
DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in extractname (called from answerauth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge."
DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in resizepacket (called from FuzzResizePacket and fuzzrfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge." However, a contributor states that a security patch (mentioned in 016162.html) is needed.
DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in extractname (called from hashquestions and fuzzutil.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge."
DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in dhcpreply (called from dhcppacket and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge."
DISPUTED Dnsmasq 2.86 has a heap-based buffer overflow in checkbadaddress (called from checkforboguswildcard and FuzzCheckForBogusWildcard). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge."