#VU94783 Integer overflow in Dnsmasq - CVE-2023-49441
Published: July 26, 2024
Dnsmasq
GNU
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow within the sha256_transform() function in hash-questions.c when comparing hashes. A remote attacker can send specially crafted data to the server, trigger an integer overflow and perform a denial of service (DoS) attack.
Remediation
External links
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2023q4/017332.html
- https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=blobdiff;f=src/hash-questions.c;h=e6304ac807a8b7802bb50208ee5a846f4d62d8b7;hp=c1ee1354433df5e4aea1fe9f4622d30eca79ce01;hb=65c2d6afd67a032f45f40d7e4d620f5d73e5f07d;hpb=b27b94cfdc5e0cad6a5a8675471e0bdc64676006