Unrated severityNVD Advisory· Published May 8, 2015· Updated May 6, 2026
CVE-2015-3294
CVE-2015-3294
Description
The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.
Affected products
2- cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2015q2/009382.htmlnvdExploit
- lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2015q2/009387.htmlnvdThird Party Advisory
- www.debian.org/security/2015/dsa-3251nvdVendor Advisory
- www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlnvdThird Party Advisory
- www.ubuntu.com/usn/USN-2593-1nvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2015-05/msg00013.htmlnvd
- www.securityfocus.com/archive/1/535354/100/1100/threadednvd
- www.securityfocus.com/bid/74452nvd
- www.securitytracker.com/id/1032195nvd
- security.gentoo.org/glsa/201512-01nvd
News mentions
0No linked articles in our index yet.