Security hole in ISC DHCPD
Summary
In January 2003 the Internet Software Consortium found holes in its DHCP server ISC dhcpd during a code review that allowed attackers to execute code remotely, usually with root privileges. Versions 3.0 to 3.0.1RC10 were affected. The bug lay in the error handling of the minires library, which is used for dynamic DNS updates.
Ideas
- An internal code review uncovered the holes before any attacks became known.
- The function for dynamic DNS updates enlarged the attack surface.
- Services with root privileges turn every hole into a system takeover.
Insights
- Proactive code audits are a sign of responsible project maintenance.
- Network services should switch to an unprivileged account after starting.
Facts
- Red Hat, SuSE, Debian and BSD/OS, among others, were affected.
- The bug was in the minires library.
References
Critique
- The report names no workarounds, such as switching off dynamic DNS updates.
Remarks
- ISC discontinued the DHCP server in 2022; its successor is Kea.
Recommendations
- Run DHCP and DNS services under their own unprivileged users.
- Plan the migration from ISC dhcpd to Kea or dnsmasq.
Links to the original source and the Web Archive open in a new tab.