Bug 770435 (CVE-2012-3411) - VUL-0: CVE-2012-3411: dnsmasq: not processing packets correctly when used with libvirt
Summary: VUL-0: CVE-2012-3411: dnsmasq: not processing packets correctly when used wit...
Status: RESOLVED WONTFIX
Alias: CVE-2012-3411
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-07-09 12:46 UTC by Sebastian Krahmer
Modified: 2014-04-10 13:14 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2012-07-09 12:46:34 UTC
Via OSS-sec:


Date: Mon, 09 Jul 2012
From: Jan Lieskovsky
Reply-To: oss-security


Hello Kurt, Steve, vendors,

  David Woodhouse reported a deficiency in the way dnsmasq,
a lightweight, easy to configure DNS forwarder and DHCP server,
when being run under libvirt, a library providing simple
virtualization API, performed processing of packets coming
outside of virtual network set for the particular guest domain.

  When libvirt was configured to provide a range of public
IP addresses to its guest domains and dnsmasq was instructed
to discard packets originating from other interfaces, than
specified on the command line via the --bind-interface option,
those packets (coming from 'prohibited' interfaces) were not
dropped properly and subsequently processed.

  A remote attacker could use this flaw to cause a distributed
denial of service, as demonstrated in the report [1] via "stream
of spoofed DNS queries producing large results".

References:
[1] https://bugzilla.redhat.com/show_bug.cgi?id=833033

Could you allocate a CVE id for this?

Thank you && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team
Comment 2 Swamp Workflow Management 2012-07-09 22:00:13 UTC
bugbot adjusting priority
Comment 4 Sebastian Krahmer 2012-07-16 07:06:03 UTC
It got a CVE at least: CVE-2012-3411
Comment 7 Sebastian Krahmer 2012-08-08 12:13:14 UTC
Ok, the rest comes from upstream. Closing since too minor.
Comment 8 Sebastian Krahmer 2012-08-08 12:13:32 UTC
.