Bug 600738 - MaraDNS: Usa-after-free when parsing csv2 zone file, containing hostnames not ending with '.' character
Summary: MaraDNS: Usa-after-free when parsing csv2 zone file, containing hostnames not...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: maradns
Version: el5
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Orphan Owner
QA Contact: Fedora Extras Quality Assurance
URL: http://bugs.debian.org/cgi-bin/bugrep...
Whiteboard:
Depends On:
Blocks: 600739 600740 600741 CVE-2010-2444
TreeView+ depends on / blocked
 
Reported: 2010-06-05 20:23 UTC by Jan Lieskovsky
Modified: 2015-01-15 16:43 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 600739 (view as bug list)
Environment:
Last Closed: 2015-01-15 16:43:08 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
Local copy of "maradns-1.4.02-parse_segfault.patch" from [2] (3.39 KB, patch)
2010-06-05 20:27 UTC, Jan Lieskovsky
no flags Details | Diff

Description Jan Lieskovsky 2010-06-05 20:23:36 UTC
Maradns upstream, in version v1.4.03 fixed following bug (from
patch changelog):

<begin quote>

This fixes a bug introduced in MaraDNS 1.3.03 (January 2007) when
I allowed '.' to be in a hostname: Hostnames that incorrectily not
end with a dot result in a string being deallocated then used.

MaraDNS 1.2 does not have this issue.

This issue can not be exploited from zones loaded using DNS's zone
transfer mechanism; fetchzone filters data obtained this way.  This issue
can only be exploited in the unusual case of an attacker having control
of the contents of a csv2 zone file to be parsed by MaraDNS.

This issue, on Linux systems, results in a null pointer dereference that
does not appear to be exploitable.

This patch cleanly patches MaraDNS 1.4.02 and against 1.3.07.09.

<end quote>

Red Hat Security Response Team wouldn't consider this to bei a security
issue, as it's just NULL pointer dereference and requires the attacker
to have control of the contenst of a csv2 zone file to be parsed
by MaraDNS (which is quite unlikely). But it's still a bug / deficiency,
which should be addressed.

References:
  [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584587
  [2] http://maradns.org/download/maradns-1.4.02-parse_segfault.patch

Comment 1 Jan Lieskovsky 2010-06-05 20:27:48 UTC
Created attachment 421489 [details]
Local copy of "maradns-1.4.02-parse_segfault.patch" from [2]

While current EPEL-5 version of MaraDNS seems to already contain
some hunks of this patch, Michael, please double-check && rebuild
if necessary (at least first hunk seems applicable).

Thanks, Jan.

Comment 2 Eric Christensen 2015-01-15 16:43:08 UTC
This package has been retired.  This ticket should be reopened if the package is unretired.


Note You need to log in before you can comment on or make changes to this bug.