MNBSD-2020-5: Heap overflow in dhclient(8) DHCP option 119 parsing

Severity: Unknown

Affected Package: dhclient

Summary: Heap overflow in dhclient(8) DHCP option 119 parsing

Description

When parsing DHCP option 119 data, dhclient(8) computes the uncompressed domain search list length in order to allocate a buffer. The length computation failed to handle certain malformed input, resulting in a heap overflow when the uncompressed list was copied into an inadequately sized buffer. A malicious DHCP server, or an attacker able to spoof DHCP responses, could exploit this.

Affected Versions

dhclient

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2020-7461

Published: September 02, 2020
Last Modified: September 02, 2020