Dnsmasq "setup_reply ()" DoS Vulnerability
Dnsmasq "setup_reply ()" DoS Vulnerability
Release date:
Updated on:
Affected Systems:
Dnsmasq
Description:
CVE (CAN) ID: CVE-2015-3294
Dnsmasq is a lightweight DNS forwarder and DHCP server.
Dnsmasq has a Denial-of-Service vulnerability. By constructing a DNS request package, remote users can exploit this vulnerability to read the process memory content, causing the target service to crash.
<* Source: Nick Sampanis
*>
Suggestion:
Vendor patch:
Dnsmasq
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2015q2/009382.html
Http://thekelleys.org.uk/gitweb? P = dnsmasq. git; a = commit; h = ad4a8ff7d9097008d7623df8543df435bfddeac8
DNSmasq and Named in Ubuntu 10.10 may conflict.
Use DNSmasq in Ubuntu 8.10 To provide DNS and DHCP services
Use DNSmasq to build a small Intranet DNS
Install and configure Cobbler + DNSmasq + tftpd-hpa in Ubuntu Server 12.04
For details about DNSmasq, click here
DNSmasq: click here
This article permanently updates the link address: