Referenced CVEs:
CVE-2009-2957, CVE-2009-2958
Description:
===========================================================Ubuntu Security Notice USN-827-1 September 01, 2009dnsmasq vulnerabilitiesCVE-2009-2957, CVE-2009-2958===========================================================A security issue affects the following Ubuntu releases:Ubuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 8.04 LTS: dnsmasq-base 2.41-2ubuntu2.2Ubuntu 8.10: dnsmasq-base 2.45-1ubuntu1.1Ubuntu 9.04: dnsmasq-base 2.47-3ubuntu0.1In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:IvAin Arce, Pablo HernAin Jorge, Alejandro Pablo Rodriguez, MartA*n Coco,Alberto SoliAto Testa and Pablo Annetta discovered that Dnsmasq did notproperly validate its input when processing TFTP requests for files withlong names. A remote attacker could cause a denial of service or executearbitrary code with user privileges. Dnsmasq runs as the 'dnsmasq' user bydefault on Ubuntu. (CVE-2009-2957)Steve Grubb discovered that Dnsmasq could be made to dereference a NULLpointer when processing certain TFTP requests. A remote attacker couldcause a denial of service by sending a crafted TFTP request.(CVE-2009-2958)
More...