LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-17-2016, 01:54 PM   #1
Guttorm
Senior Member
 
Registered: Dec 2003
Location: Trondheim, Norway
Distribution: Debian and Ubuntu
Posts: 1,453

Rep: Reputation: 447Reputation: 447Reputation: 447Reputation: 447Reputation: 447
getaddrinfo bug in glibc (CVE-2015-7547) questions?


Hello

I just about the bug. As far as I understand it's this:

If you do reverse DNS lookups, and the result comes from an evil DNS server, bad things can happen. (if length > 2048) Now people are patching and rebooting.

My question is if it's only the the DNS servers need fixing. If I boot with a old live cd and reverse lookup some nasty IP address, what will happen?
 
Old 02-18-2016, 12:32 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
It's not specifically DNS that needs patching (we're talking about an adversary exploiting what is "allowed" reply size-wise within the DNS RFCs) but any machine using an affected Glibc version that uses AF_UNSPEC-type lookups and uses unfiltered replies (doesn't say anything about the type) or receives unfiltered lookup results from other systems.
 
Old 02-18-2016, 01:29 AM   #3
Guttorm
Senior Member
 
Registered: Dec 2003
Location: Trondheim, Norway
Distribution: Debian and Ubuntu
Posts: 1,453

Original Poster
Rep: Reputation: 447Reputation: 447Reputation: 447Reputation: 447Reputation: 447
Ok. We have a DNS server using BIND, and as far as I understand, it's doing the actual resolving of reverse DNS lookups. Or am I incorrect?

The DNS server has been patched, but I was thinking it could maybe do the filtering of replies? A live CD gets the DNS from DHCP, so I was wondering if it was a way to protect them against this.
 
Old 02-18-2016, 06:22 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by Guttorm View Post
Ok. We have a DNS server using BIND, and as far as I understand, it's doing the actual resolving of reverse DNS lookups. Or am I incorrect?
A Domain Name server can be configured in many way: authoritative name server, slave, caching name server, forwarder. Then there's devices running Linux who have a resolver stub as libraries like Glibc provide them (uClibc, dietlibc and musl seem unaffected AFAIK). These are separate things ..


Quote:
Originally Posted by Guttorm View Post
The DNS server has been patched, but I was thinking it could maybe do the filtering of replies? A live CD gets the DNS from DHCP, so I was wondering if it was a way to protect them against this.
.. so while you may patch DNS as part of your mitigation strategy this only combats symptoms but does not solve the cause IMHO.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
glibc security patch cve-2015-7547 ReaperX7 Slackware 16 02-22-2016 05:04 AM
LXer: CVE-2015-7547: glibc getaddrinfo stack-based buffer overflow LXer Syndicated Linux News 0 02-16-2016 04:12 PM
rpm for BIND 9 version 9.9.7-P2 (fix CVE-2015-5477) rhel tuccero9 Red Hat 10 09-08-2015 08:31 AM
[SOLVED] Has anyone patched for CVE-2015-5477 rdegrad Linux - Networking 0 08-07-2015 12:45 AM
Glibc warning concerning use of getaddrinfo() in static library dwhitney67 Programming 3 06-19-2009 01:43 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration