dnsmasq-2.45-1.1.1AXS3

エラータID: AXSA:2009-389:01

Release date: 
Tuesday, September 8, 2009 - 20:00
Subject: 
dnsmasq-2.45-1.1.1AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

Dnsmasq is lightweight, easy to configure DNS forwarder and DHCP server. It is designed to provide DNS and, optionally, DHCP, to a small network. It can serve the names of local machines which are not in the global DNS. The DHCP server integrates with the DNS server and allows machines with DHCP-allocated addresses to appear in the DNS with names configured either in each host or in a central configuration file. Dnsmasq supports static and dynamic DHCP leases and BOOTP for network booting of diskless machines.
Fixed bugs:
CVE-2009-2957
Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.
CVE-2009-2958
The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.

Solution: 

Update packages

Additional Info: 

N/A

Download: 

SRPMS
  1. dnsmasq-2.45-1.1.1AXS3.src.rpm
    MD5: bc2b4d5347cd60520939c514a6327058
    SHA-256: 632d0c1092fa7394064c018a2139c8e229fa984723edb06a422c97c003bd0f80
    Size: 383.28 kB

Asianux Server 3 for x86
  1. dnsmasq-2.45-1.1.1AXS3.i386.rpm
    MD5: 79956f2174af6adafa16d2afb3329af4
    SHA-256: de4801e3399765c2d0413a885e112e498bde060eedfed7ca36b754ebdd8836c5
    Size: 165.38 kB

Asianux Server 3 for x86_64
  1. dnsmasq-2.45-1.1.1AXS3.x86_64.rpm
    MD5: 23bfa975b5631cb55678efbf7c890fa8
    SHA-256: 427cbea7f124ae4f5f834092b54b500a10adb3b5314ea4bbc93d3490cb576f09
    Size: 168.54 kB