← Vulnerability feed

Vulnerability record · CVE-2009-2957 · published 2 September 2009

CVE-2009-2957: Thekelleys dnsmasq memory buffer overflow vulnerability

Thekelleys · Dnsmasq

Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

6.8 CVSS 2.0 Medium EPSS 13% · top 3.9% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-2957 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45951Thekelleys dnsmasq out-of-bounds write vulnerabilityDnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the ve…EPSS 2.6%9.8CVE-2021-45952Thekelleys dnsmasq out-of-bounds write vulnerabilityDnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-4595…EPSS 2.6%9.8CVE-2021-45953Thekelleys dnsmasq out-of-bounds write vulnerabilityDnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the vendor's position is that CVE-2…EPSS 2.6%9.8CVE-2021-45954Thekelleys dnsmasq out-of-bounds write vulnerabilityDnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45…EPSS 2.6%9.8CVE-2021-45955Thekelleys dnsmasq out-of-bounds write vulnerabilityDnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper boun…EPSS 2.5%9.8CVE-2021-45956Thekelleys dnsmasq out-of-bounds write vulnerabilityDnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-4595…EPSS 2.6%9.8CVE-2021-45957Thekelleys dnsmasq out-of-bounds write vulnerabilityDnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is…EPSS 2.4%9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed

Source: NIST National Vulnerability Database (record CVE-2009-2957), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.