Vulnerability Bulletins

DSA-3251 dnsmasq - security update

   
Affected software Debian
 
Nick Sampanis discovered that dnsmasq, a small caching DNS proxy andDHCP/TFTP server, did not properly check the return value of thesetup_reply() function called during a TCP connection, which is usedthen as a size argument in a function which writes data on the clientsconnection. A remote attacker could exploit this issue via a speciallycrafted DNS request to cause dnsmasq to crash, or potentially to obtainsensitive information from process memory.

More info:

https://www.debian.org/security/2015/dsa-3251