|
Message-ID: <6922.1216840848@devserv.devel.redhat.com> Date: Wed, 23 Jul 2008 15:20:48 -0400 From: Josh Bressers <bressers@...hat.com> To: Jamie Strandboge <jamie@...onical.com> cc: "Steven M. Christey" <coley@...us.mitre.org>, oss-security@...ts.openwall.com Subject: Re: CVE request for dnsmasq DoS On 8 July 2008, Jamie Strandboge wrote: > > I finally had time to develop a PoC and confirm this on my own. A client > need only send a DHCPREQUEST for an IP address not on the same network > as dnsmasq. Eg: > > 1. dnsmasq listening on and giving IP addresses for 192.168.122.0/24 > 2. client requests IP address on another network, such as 192.168.0.1 > 3. dnsmasq 2.25 (and presumably earlier) crashes > It seems there is also a problem with newer dnsmasq that is very similar to this: http://bugs.gentoo.org/show_bug.cgi?id=232523 That problem appears to be pretty much the same thing, but affecting versions 2.43 - 2.45 Did this ever get a CVE id? I presume this new flaw will need one as well. Thanks. -- JB
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.