Date: Sat, 12 Jul 2008 08:28:07 -0400 From: Jamie Strandboge <jamie@...onical.com> To: oss-security@...ts.openwall.com Cc: coley@...us.mitre.org Subject: Re: CVE request for dnsmasq DoS On Thu, 03 Jul 2008, Jamie Strandboge wrote: > On Tue, 01 Jul 2008, Steven M. Christey wrote: > > > I'm not sure I fully understand Thierry Carrez' comment about the security > > implications of this issue. It seems like an exploit would require a > > malicious DHCP server, in which case isn't DHCP service already > > compromised? If so, then a crash of dnsmasq (null dereference?) doesn't > > seem to be any worse than the loss of DHCP itself. > > > I haven't had time to develop a PoC, but from the dnsmasq 2.26 announce > page at , a client need only send a crafted renewal request to crash > the server. Thierry's comments were only for trying to reproduce the > problem and test the patch. > (resending as the first one didn't make it to the list) I finally had time to develop a PoC and confirm this on my own. A client need only send a DHCPREQUEST for an IP address not on the same network as dnsmasq. Eg: 1. dnsmasq listening on and giving IP addresses for 192.168.122.0/24 2. client requests IP address on another network, such as 192.168.0.1 3. dnsmasq 2.25 (and presumably earlier) crashes This can happen in normal operation with roaming users, but can also happen with a malicious request. Attached is a script to easily test for this (requires python scapy). Jamie -- Ubuntu Security Engineer | http://www.ubuntu.com/ Canonical Ltd. | http://www.canonical.com/ View attachment "dhcp_request.py" of type "text/x-python" (1928 bytes) Download attachment "signature.asc" of type "application/pgp-signature" (190 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.