Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA 245-1 Critical: DHCP3 Packet Storm Remote Exploit

debian
Calendar Grey January 28, 2003
Debian Logo
Debian Security Advisory DSA 245-1 Debian Security Information Martin Schulze January 28th, 2003 Deb
There is a bug in the dhcrelay causing it to send a continuing packet storm towards the configured DHCP server(s) in case of a malicious BOOTP packet.

Summary

Florian Lohoff discovered a bug in the dhcrelay causing it to send a
continuing packet storm towards the configured DHCP server(s) in case
of a malicious BOOTP packet, such as sent from buggy Cisco switches.

When the dhcp-relay receives a BOOTP request it forwards the request
to the DHCP server using the broadcast MAC address ff:ff:ff:ff:ff:ff
which causes the network interface to reflect the packet back into the
socket. To prevent loops the dhcrelay checks whether the
relay-address is its own, in which case the packet would be dropped.
In combination with a missing upper boundary for the hop counter an
attacker can force the dhcp-relay to send a continuing packet storm
towards the configured dhcp server(s).

This patch introduces a new commandline switch ``-c maxcount' and
people are advised to start the dhcp-relay with ``dhcrelay -c 10'
or a smaller number, which will only create that many packets.

The dhcrelay program from the ``dhcp' package does not seem to be
affected since DHCP packets are ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: dhcp3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here