← All CVEs

CVE-2009-2958

medium · 4.3

The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.

4.3
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2009-09-02
Published

AV:N/AC:M/Au:N/C:N/I:N/A:P

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
thekelleysdnsmasq<= 2.49
thekelleysdnsmasq0.4
thekelleysdnsmasq0.5
thekelleysdnsmasq0.6
thekelleysdnsmasq0.7
thekelleysdnsmasq0.95
thekelleysdnsmasq0.96
thekelleysdnsmasq0.98
thekelleysdnsmasq0.992
thekelleysdnsmasq0.996
thekelleysdnsmasq1.0
thekelleysdnsmasq1.2
thekelleysdnsmasq1.3
thekelleysdnsmasq1.4
thekelleysdnsmasq1.5
thekelleysdnsmasq1.6
thekelleysdnsmasq1.7
thekelleysdnsmasq1.8
thekelleysdnsmasq1.9
thekelleysdnsmasq1.10
thekelleysdnsmasq1.11
thekelleysdnsmasq1.12
thekelleysdnsmasq1.13
thekelleysdnsmasq1.14
thekelleysdnsmasq1.15
thekelleysdnsmasq1.16
thekelleysdnsmasq1.17
thekelleysdnsmasq1.18
thekelleysdnsmasq2.0
thekelleysdnsmasq2.1
thekelleysdnsmasq2.2
thekelleysdnsmasq2.3
thekelleysdnsmasq2.4
thekelleysdnsmasq2.5
thekelleysdnsmasq2.6
thekelleysdnsmasq2.7
thekelleysdnsmasq2.8
thekelleysdnsmasq2.9
thekelleysdnsmasq2.10
thekelleysdnsmasq2.11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-2958