Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 23 Jul 2008 15:20:48 -0400
From: Josh Bressers <bressers@...hat.com>
To: Jamie Strandboge <jamie@...onical.com>
cc: "Steven M. Christey" <coley@...us.mitre.org>,
        oss-security@...ts.openwall.com
Subject: Re: CVE request for dnsmasq DoS

On 8 July 2008, Jamie Strandboge wrote:
> 
> I finally had time to develop a PoC and confirm this on my own. A client
> need only send a DHCPREQUEST for an IP address not on the same network
> as dnsmasq. Eg:
> 
> 1. dnsmasq listening on and giving IP addresses for 192.168.122.0/24
> 2. client requests IP address on another network, such as 192.168.0.1
> 3. dnsmasq 2.25 (and presumably earlier) crashes
> 

It seems there is also a problem with newer dnsmasq that is very similar to
this:
http://bugs.gentoo.org/show_bug.cgi?id=232523

That problem appears to be pretty much the same thing, but affecting
versions 2.43 - 2.45

Did this ever get a CVE id?

I presume this new flaw will need one as well.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.