Vulnerabilities in FreeBSD, IPnet, and Nucleus NET related to compression implementation errors in DNS

The research groups Forescout Research Labs and JSOF Research published the results of their joint investigation into the security of various implementations of compression schemes used for packing duplicate names in DNS, mDNS, DHCP, and IPv6 RA messages (packing duplicate parts of domains in messages that include multiple names). The study identified nine vulnerabilities, summarized under the code name NAME:WRECK.

Issues were found in FreeBSD, as well as in the IPnet, Nucleus NET, and NetX networking subsystems, which are prevalent in real-time operating systems such as VxWorks, Nucleus, and ThreadX, used in automation devices, storage systems, medical devices, avionics, printers, and consumer electronics. It is estimated that at least 100 million devices are affected by these vulnerabilities.

  • The vulnerability in FreeBSD (CVE-2020-7461) allowed for remote code execution through the sending of a specially crafted DHCP packet by an attacker within the same local network as the victim. Processing this packet by a vulnerable DHCP client led to a buffer overflow. The issue was mitigated by the fact that the dhclient process, which contained the vulnerability, ran with reduced privileges in a Capsicum isolated environment, from which an additional vulnerability would need to be discovered to escape.

    The core of the error lies in the improper validation of parameters in the DHCP server's returned packet with option 119, which allows a 'domain search' list to be passed to a resolver. Incorrect calculation of the buffer size needed to hold the unpacked data led to controlled attacker information being written beyond the allocated buffer. domain namesIn FreeBSD, the problem was resolved back in September of last year. The vulnerability can only be exploited with access to the local network.

  • The vulnerability in the embedded networking stack IPnet, used in the RTOS VxWorks, potentially allows code execution on the DNS client side due to incorrect handling of DNS message compression. It turned out that this vulnerability was first identified by Exodus back in 2016, but it was never fixed. A new inquiry to Wind River also went unanswered, leaving devices with IPnet vulnerable.
  • In the TCP/IP stack Nucleus NET, supported by Siemens, 6 vulnerabilities have been identified, two of which could lead to remote code execution, while four could initiate a denial of service. The first critical issue is related to an error in unpacking compressed DNS messages, and the second is due to improper parsing of domain name labels. Both issues result in a buffer overflow when processing specially crafted DNS responses.

    To exploit these vulnerabilities, an attacker merely needs to send a specially crafted response to any legitimate request made from a vulnerable device, for example, by conducting a MITM attack and injecting into the traffic between the DNS server and the victim. If the attacker has access to the local network, they can launch a DNS server that attempts to attack the problematic devices by sending mDNS requests in broadcast mode.

  • A vulnerability in the NetX network stack (Azure RTOS NetX), developed for ThreadX RTOS and made open after being acquired by Microsoft in 2019, was limited to denial of service. The issue arises from an error in parsing compressed DNS messages in the resolver implementation.

Among the checked network stacks that did not show vulnerabilities associated with the compression of repeated data in DNS messages are the lwIP, Nut/Net, Zephyr, uC/TCP-IP, FreeRTOS+TCP, OpenThread, and FNET projects. Notably, the first two (Nut/Net and lwIP) do not support compression in DNS messages at all, while the others implement this operation without errors. Additionally, it is noted that the same researchers had previously identified similar vulnerabilities in the Treck, uIP, and PicoTCP stacks.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster