Oval Definition:oval:org.cisecurity:def:127
Revision Date:2016-02-08Version:2
Title:DSA-3251-1 -- dnsmasq -- security update
Description:Nick Sampanis discovered that dnsmasq, a small caching DNS proxy and DHCP/TFTP server, did not properly check the return value of the setup_reply() function called during a TCP connection, which is used then as a size argument in a function which writes data on the client's connection. A remote attacker could exploit this issue via a specially crafted DNS request to cause dnsmasq to crash, or potentially to obtain sensitive information from process memory.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2015-3294
DSA-3251-1
Platform(s):Debian 8
Debian GNU/kFreeBSD 7.0
Debian GNU/Linux 7.0
Product(s):dnsmasq
Definition Synopsis
  • Debian 7
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND dnsmasq is earlier than 0:2.62-3+deb7u2
  • OR Debian 8
  • Debian 8 is installed
  • AND dnsmasq is earlier than 0:2.72-3+deb8u1
  • BACK