CVE-2015-3294
Last modified
CVE-2015-3294 is a vulnerability of currently unknown severity. The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.. EPSS estimates a 4.46% chance of exploitation in the next 30 days.
Description
The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Thekelleys | Dnsmasq | <= 2.73 | Rc3 |
| Oracle | Solaris | 11.2 | — |
References
- http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2015q2/009387.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3251Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlThird Party Advisory
- http://www.ubuntu.com/usn/USN-2593-1Vendor Advisory
- http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2015q2/009387.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3251Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlThird Party Advisory
- http://www.ubuntu.com/usn/USN-2593-1Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3294?
How severe is CVE-2015-3294?
How do I fix CVE-2015-3294?
Are you affected by CVE-2015-3294?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
