Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 628566 (CVE-2017-12865) - <net-misc/connman-1.35-r1: DNS response may cause a remote denial of service (CVE-2017-12865)
Summary: <net-misc/connman-1.35-r1: DNS response may cause a remote denial of service ...
Status: RESOLVED FIXED
Alias: CVE-2017-12865
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B2 [glsa+ cve]
Keywords:
Depends on: CVE-2017-5716
Blocks:
  Show dependency tree
 
Reported: 2017-08-22 06:04 UTC by Aleksandr Wagner (Kivak)
Modified: 2018-12-02 15:47 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-08-22 06:04:07 UTC
From $URL:

A flaw was found in ConnMan 1.34 and earlier. Connman DNS-proxy feature forwards DNS queries from the localhost to an external DNS server. The DNS resonse handled from an external DNS server may cause a remote denial-of-service or possibly remote code execution if malformed. The flaw is in the lenght of the variable "name" in src/dnsproxy.c.

Upstream patch:

https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=5c281d182ecdd0a424b64f7698f32467f8f67b71
Comment 1 Aleksandr Wagner (Kivak) 2017-09-24 14:18:05 UTC
Version 1.35 is now in the tree:

commit 6e6adfa40771badfb21c1ff3f71aaf464b754f34
Author: Yixun Lan <dlan@gentoo.org>
Date:   Tue Sep 5 10:36:29 2017 +0800

    net-misc/connman: version bump 1.35
    
    Package-Manager: Portage-2.3.6, Repoman-2.3.3

Future stabilization will be done in bug 630028.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2018-12-02 15:47:18 UTC
This issue was resolved and addressed in
 GLSA 201812-02 at https://security.gentoo.org/glsa/201812-02
by GLSA coordinator Aaron Bauman (b-man).