|
Message-ID: <407133982.12056890.1358523105381.JavaMail.root@redhat.com> Date: Fri, 18 Jan 2013 10:31:45 -0500 (EST) From: Jan Lieskovsky <jlieskov@...hat.com> To: oss-security@...ts.openwall.com Cc: "Steven M. Christey" <coley@...us.mitre.org>, Tomas Hozza <thozza@...hat.com>, Josh Stone <jistone@...hat.com> Subject: Re: CVE Request -- dnsmasq: Incomplete fix for the CVE-2012-3411 issue Simultaneously in the second breath it needs to be said (yet) that this would be issue of a lower severity (for TCP) than for the UDP protocol case (for TCP it's not that easy to spoof the source IP address as for UDP). Thank you && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team ----- Original Message ----- Hello Kurt, Steve, vendors, the CVE-2012-3411 identifier has been originally assigned to the following issue: When dnsmasq is used in conjunctions with certain configurations of libvirtd, network packets from prohibited networks (e.g. packets that should not be passed in) may be sent to the dnsmasq application and processed. This can result in DNS amplification attacks for example. [1] http://www.openwall.com/lists/oss-security/2012/07/12/5 Later it was found: [2] https://bugzilla.redhat.com/show_bug.cgi?id=894486 [3] https://bugzilla.redhat.com/show_bug.cgi?id=894486#c3 the upstream patch for CVE-2012-3411 it not to be working properly, as it still allowed (from [3]): * replies to remote TCP-protocol based DNS queries (UDP protocol ones were corrected, but TCP ones not) from prohibited networks, when the --bind-dynamic option was used, * when --except-interface lo option was used dnsmasq didn't answer local or remote UDP DNS queries, but still allowed TCP protocol based DNS queries, * when --except-interface lo option was not used local / remote TCP DNS queries were also still answered by dnsmasq. Could you allocate a new CVE identifier for this? (as an incomplete fix for CVE-2012-3411 issue) Thank you && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.