CVE-2009-2957

Priority
Description
Heap-based buffer overflow in the tftp_request function in tftp.c in
dnsmasq before 2.50, when --enable-tftp is used, might allow remote
attackers to execute arbitrary code via a long filename in a TFTP packet,
as demonstrated by a read (aka RRQ) request.
Assigned-to
jdstrand
Notes
jdstrandDapper does not have tftp code
Package
Upstream:released (2.50-1)
More Information

Updated: 2020-03-18 22:00:48 UTC (commit 2ea7df7bd1e69e1e489978d2724a936eb3faa1b8)