Vigil@nce - ISC DHCP: denial of service via DHCPv6 and DDNS
January 2012 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can send DNS IPv6 updates, in order to stop ISC DHCP.
Severity: 2/4
Creation date: 13/01/2012
IMPACTED PRODUCTS
Fedora
ISC DHCP
DESCRIPTION OF THE VULNERABILITY
The ISC DHCP server supports IPv6, and can process updates via Dynamic DNS.
When a DDNS TEXT or PTR message is received, the ddns_update_lease_text() and ddns_update_lease_ptr() functions update data. However, if the DHCPv6 lease is not active, a NULL pointer (lease6->addr) is dereferenced, or an update can be done on a freed structure.
An attacker can therefore send DNS IPv6 updates, in order to stop ISC DHCP.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN





News













