CVE-2015-3294

The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thekelleys:dnsmasq:*:rc3:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-05-08 14:59

Updated : 2024-02-04 18:53


NVD link : CVE-2015-3294

Mitre link : CVE-2015-3294

CVE.ORG link : CVE-2015-3294


JSON object : View

Products Affected

thekelleys

  • dnsmasq

oracle

  • solaris
CWE
CWE-19

Data Processing Errors