SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#854315

ISC DHCPD contains format string vulnerability when logging DNS-update requests

Overview

The DHCP daemon (DHCPD) is a server that is used to allocate network addresses and assign configuration parameters to dynamically configured hosts. A format string vulnerability may permit an intruder to execute code with the privileges of the DHCP daemon (typically root).

I. Description

The Internet Software Consortium (ISC) produces a DHCP server. DHCPD listens for requests from client machines connecting to the network. Versions 3 to 3.0.1rc8 inclusive of DHCPD contain an option (NSUPDATE) that is compiled in by default. NSUPDATE allows the DHCP server to send an update to the DNS server after processing a DHCP request. The DNS server responds by sending a message back to the DHCP server. The response from the DNS server can contain user-supplied data. When this message is received, the DHCP server logs the transaction. A format string vulnerability exists in the DHCPD code that logs the transaction. This vulnerability may permit an attacker to execute code with the privileges of the DHCP daemon.

II. Impact

A remote attacker can execute arbitrary code on the vulnerable host with the privileges of the DHCP server (DHCPD), typically root.

III. Solution

Obtain a patch from vendor.

If you cannot upgrade, apply the following patch.

--- common/print.c Tue Apr 9 13:41:17 2002
+++ common/print.c.patched Tue Apr 9 13:41:56 2002
@@ -1366,8 +1366,8 @@
*s++ = '.';
*s++ = 0;
if (errorp)
- log_error (obuf);
+ log_error ("%s",obuf);
else
- log_info (obuf);
+ log_info ("%s",obuf);
}
#endif /* NSUPDATE */

Systems Affected

VendorStatusDate NotifiedDate Updated
3ComUnknown7-May-2002
AlcatelVulnerable29-May-2002
Apple Computer Inc.Not Vulnerable14-May-2002
AT&TUnknown7-May-2002
AvayaUnknown7-May-2002
BSDIUnknown6-May-2002
CacheFlow Inc.Unknown7-May-2002
Check PointUnknown15-May-2002
Cisco Systems Inc.Unknown7-May-2002
Compaq Computer CorporationUnknown6-May-2002
Computer AssociatesUnknown7-May-2002
ConectivaVulnerable13-May-2002
Cray Inc.Not Vulnerable13-May-2002
Data GeneralUnknown6-May-2002
DebianUnknown6-May-2002
DellUnknown7-May-2002
F5 NetworksNot Vulnerable8-May-2002
FreeBSDVulnerable7-May-2002
Fujitsu LimitedNot Vulnerable14-May-2002
Guardian Digital Inc. Unknown6-May-2002
Hewlett-Packard CompanyNot Vulnerable8-May-2002
HoneywellUnknown7-May-2002
IBMNot Vulnerable7-May-2002
Inktomi CorporationUnknown7-May-2002
ISCVulnerable8-May-2002
LantronixUnknown7-May-2002
LinksysUnknown7-May-2002
Lotus Development CorporationNot Vulnerable8-May-2002
MandrakeSoftUnknown6-May-2002
MarconiUnknown7-May-2002
Microsoft CorporationNot Vulnerable8-May-2002
NEC CorporationNot Vulnerable14-May-2002
NetBSDVulnerable8-May-2002
Nortel NetworksNot Vulnerable9-May-2002
NovellUnknown15-May-2002
OpenBSDUnknown6-May-2002
OracleUnknown7-May-2002
Red Hat Inc.Not Vulnerable31-May-2002
SequentUnknown6-May-2002
SGINot Vulnerable6-May-2002
Sony CorporationUnknown6-May-2002
Sun Microsystems Inc.Not Vulnerable10-Jun-2002
The SCO Group (SCO Linux)Unknown6-May-2002
The SCO Group (SCO UnixWare)Unknown6-May-2002
UnisysUnknown6-May-2002
VerilinkUnknown7-May-2002
Wind River Systems Inc.Unknown7-May-2002
XeroxNot Vulnerable19-Jul-2002

References


http://www.ngsec.com/docs/advisories/NGSEC-2002-2.txt
http://www.isc.org/products/DHCP/
http://www.securityfocus.com/bid/4701

Credit

The CERT Coordination Center acknowledges Next Generation Security Technologies as the discoverer of this vulnerability and thanks them and The Internet Software Consortium (ISC) for their cooperation, reporting and analysis of this vulnerability.

This document was written by Ian A. Finlay.

Other Information

Date Public:2002-05-08
Date First Published:2002-05-08
Date Last Updated:2003-01-13
CERT Advisory:CA-2002-12
CVE-ID(s):CAN-2002-0702
NVD-ID(s):CAN-2002-0702
US-CERT Technical Alerts: 
Metric:46.17
Document Revision:47

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader