Makes mDNS ddos amplification attack possible

Bug #1570788 reported by Mattias Wadenstein
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
avahi (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Apparently mDNS can be used for ddos amplification, see for instance https://mdns.shadowserver.org/ and https://www.us-cert.gov/ncas/alerts/TA14-017A

Steps to reproduce:

dig @rusk.hpc2n.umu.se -p 5353 -t ptr _services._dns-sd._udp.local

The response is supposedly 2-10 times the size of the query, making for a moderate but noticeable amplification.

Workarounds are easy, but not responding outside localnet by default is probably reasonable for mDNS.

Reproduced at at least trusty and precise, would be very surprised if it didn't also apply to xenial but I left my xenial laptop at home today. :)

ProblemType: Bug
DistroRelease: Ubuntu 12.04
Package: avahi-daemon 0.6.30-5ubuntu2.1
ProcVersionSignature: Ubuntu 3.13.0-83.127~precise1-generic 3.13.11-ckt35
Uname: Linux 3.13.0-83-generic x86_64
NonfreeKernelModules: openafs
ApportVersion: 2.0.1-0ubuntu17.13
Architecture: amd64
Date: Fri Apr 15 12:12:22 2016
MarkForUpload: True
ProcEnviron:
 LANGUAGE=en_US:en
 TERM=xterm
 PATH=(custom, no user)
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: avahi
UpgradeStatus: No upgrade log present (probably fresh install)

CVE References

Revision history for this message
Mattias Wadenstein (maswan) wrote :
information type: Private Security → Public Security
Revision history for this message
Trent Lloyd (lathiat) wrote :

Thanks for the report.

I was interestingly unable to reproduce this when testing, so I will dig in further and try to determine why.

Revision history for this message
My Karlsson (mykarlsson-deactivatedaccount) wrote :

I am able to reproduce, but only on IPv6. Passing the -4 flag to dig resulted in connection timed out.

Revision history for this message
My Karlsson (mykarlsson-deactivatedaccount) wrote :

Apparently that wasn't the case, from another host I was able to reproduce it with IPv4 as well.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I think this was CVE-2017-6519, which was fixed a long time ago.

I am closing this bug, please feel free to open a new bug if you can reproduce with a more recent version of Ubuntu. Thanks!

Changed in avahi (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.