-
Notifications
You must be signed in to change notification settings - Fork 825
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request from GHSA-q9cp-8wcq-7pfr
* Prevent heap buffer overflow when parsing DNS packet * Fixed incorrect check in get_name*()
- Loading branch information
Showing
1 changed file
with
12 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
d1c5e4d
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
hi @sauwming from the GitHub Advisory Database and CVE team π could you provide any more details about how GHSA-q9cp-8wcq-7pfr/CVE-2023-27585 is different than GHSA-p6g5-v97c-w5q4/CVE-2022-24793 since they are extremely similar? thanks!
d1c5e4d
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, both are very similar since they both happen when parsing a DNS packet, and the problem was found using the same method, i.e. fuzzing.
We have fixed the first one in the first SA but as it turned out, there were still more issues found when using a different seed input.
The difference is that the first issue was in parsing the query record
parse_query()
, while the second is inparse_rr()
.d1c5e4d
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thanks for sharing this information with us @sauwming! we've updated the descriptions of the corresponding CVEs to better differentiate them for the rest of the community (CVE-2023-27585 PR & CVE-2022-24793 PR)
d1c5e4d
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks. I have updated our SA description as well to include the difference.