← Back

CVE-2009-2957

nvd nist
Published: Sep 2, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

Affected (76)

Products: Thekelleys: Dnsmasq
1 product
Dnsmasq
Configuration A
76 vulnerable
Vulnerable SoftwareAffected Versions
Thekelleys
Up to 2.49
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.95
Version 0.96
Version 0.98
Version 0.992
Version 0.996
Version 1.0
Version 1.10
Version 1.11
Version 1.12
Version 1.13
Version 1.14
Version 1.15
Version 1.16
Version 1.17
Version 1.18
Version 1.2
Version 1.3
Version 1.4
Version 1.5
Version 1.6
Version 1.7
Version 1.8
Version 1.9
Version 2.0
Version 2.10
Version 2.11
Version 2.12
Version 2.13
Version 2.14
Version 2.15
Version 2.16
Version 2.17
Version 2.18
Version 2.19
Version 2.1
Version 2.20
Version 2.21
Version 2.22
Version 2.23
Version 2.24
Version 2.25
Version 2.26
Version 2.27
Version 2.28
Version 2.29
Version 2.2
Version 2.30
Version 2.31
Version 2.33
Version 2.34
Version 2.35
Version 2.36
Version 2.37
Version 2.38
Version 2.39
Version 2.3
Version 2.40
Version 2.41
Version 2.42
Version 2.43
Version 2.44
Version 2.45
Version 2.46
Version 2.47
Version 2.48
Version 2.4
Version 2.5
Version 2.6
Version 2.7
Version 2.8
Version 2.9

References (18)

Source: cve@mitre.org
Patch
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.