Note CVE-2015-3294

This commit is contained in:
Simon Kelley
2015-04-16 15:24:52 +01:00
parent b4c0f092d8
commit 0df29f5e23

View File

@@ -84,6 +84,9 @@ version 2.73
Fix crash on receipt of certain malformed DNS requests. Fix crash on receipt of certain malformed DNS requests.
Thanks to Nick Sampanis for spotting the problem. Thanks to Nick Sampanis for spotting the problem.
Note that this is could allow the dnsmasq process's
memory to be read by an attacker under certain
circumstances, so it has a CVE, CVE-2015-3294
Fix crash in authoritative DNS code, if a .arpa zone Fix crash in authoritative DNS code, if a .arpa zone
is declared as authoritative, and then a PTR query which is declared as authoritative, and then a PTR query which