Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 23 Jul 2008 15:20:48 -0400
From: Josh Bressers <bressers@...hat.com>
To: Jamie Strandboge <jamie@...onical.com>
cc: "Steven M. Christey" <coley@...us.mitre.org>,
        oss-security@...ts.openwall.com
Subject: Re: CVE request for dnsmasq DoS

On 8 July 2008, Jamie Strandboge wrote:
> 
> I finally had time to develop a PoC and confirm this on my own. A client
> need only send a DHCPREQUEST for an IP address not on the same network
> as dnsmasq. Eg:
> 
> 1. dnsmasq listening on and giving IP addresses for 192.168.122.0/24
> 2. client requests IP address on another network, such as 192.168.0.1
> 3. dnsmasq 2.25 (and presumably earlier) crashes
> 

It seems there is also a problem with newer dnsmasq that is very similar to
this:
http://bugs.gentoo.org/show_bug.cgi?id=232523

That problem appears to be pretty much the same thing, but affecting
versions 2.43 - 2.45

Did this ever get a CVE id?

I presume this new flaw will need one as well.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ