Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 10: 2009-10252 Critical: Dnsmasq TFTP Multiple Issues

fedora
Calendar Grey October 13, 2009
Dist Fedora Esm H88
This latest release from Fedora fixes two severe vulnerabilities in the TFTP server of dnsmasq. Protect your system immediately!
This update fixes two security issues with dnsmasq's tftp server: https://www.cve.org/CVERecord?id=CVE-2009-2957 https://www.cve.org/CVERecord?id=CVE-2009-2958

Summary

Dnsmasq is lightweight, easy to configure DNS forwarder and DHCP server.

It is designed to provide DNS and, optionally, DHCP, to a small network.

It can serve the names of local machines which are not in the global

DNS. The DHCP server integrates with the DNS server and allows machines

with DHCP-allocated addresses to appear in the DNS with names configured

either in each host or in a central configuration file. Dnsmasq supports

static and dynamic DHCP leases and BOOTP for network booting of diskless

machines.

Update Information:

This update fixes two security issues with dnsmasq's tftp server: https://www.cve.org/CVERecord?id=CVE-2009-2957 https://www.cve.org/CVERecord?id=CVE-2009-2958

Change Log

* Mon Oct 5 2009 Mark McLoughlin - 2.46-2 - Fix multiple TFTP server vulnerabilities (CVE-2009-2957, CVE-2009-2958) * Mon Dec 29 2008 Matěj Cepl - 2.45-2 - rebuilt

References


[ 1 ] Bug #519020 - CVE-2009-2957, CVE-2009-2958 dnsmasq: multiple vulnerabilities in TFTP server https://bugzilla.redhat.com/show_bug.cgi?id=519020

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update dnsmasq' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: dnsmasq
Product: Fedora 10
Version: 2.46
Release: 2.fc10
Summary: A lightweight DHCP/caching DNS server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here