| From: |
| opensuse-security@opensuse.org |
| To: |
| opensuse-updates@opensuse.org |
| Subject: |
| openSUSE-SU-2011:0342-1 (important): dhcpcd security update |
| Date: |
| Fri, 15 Apr 2011 22:02:11 +0200 (CEST) |
| Message-ID: |
| <20110415200211.0B62C32130@maintenance.suse.de> |
| Archive-link: |
| Article, Thread
|
openSUSE Security Update: dhcpcd security update
______________________________________________________________________________
Announcement ID: openSUSE-SU-2011:0342-1
Rating: important
References: #564441 #565030 #574938 #577402 #601704 #654649
#657402 #668194 #675052
Cross-References: CVE-2011-0996
Affected Products:
openSUSE 11.2
______________________________________________________________________________
An update that solves one vulnerability and has 8 fixes is
now available.
Description:
This update fixes the following security issue:
A rogue DHCP server could instruct clients to use a host
name that contains shell meta characters. Since many
scripts in the system do not expect unusal characters in
the system's host name the DHCP client needs to sanitize
the host name offered by the server (CVE-2011-0996).
This update also fixes the following non-security issues:
- 564441: e1000 and dhcpd hickup
- 565030: dhcpcd not using router component of dhcp server
option 33 (Static Route)
- 574938: Sysem Update Fails to deploy to Primary serve.
- 577402: dhcpcp with Patch bnc#565030 has netlink error
with /32 netmask
- 601704: dhcpcd: ignores link carrier and does not
retransmit
- 654649: dhcpcd ignores -G (--nogateway) option and sets
default route
- 657402: dhcpcd sends RENEWAL as ethernet broadcast
instead of unicast
- 668194: dhcp client not working properly in Xen domU due
to partial checksum offload
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.2:
zypper in -t patch dhcpcd-4346
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.2 (i586 x86_64):
dhcpcd-3.2.3-47.64.1
References:
http://support.novell.com/security/cve/CVE-2011-0996.html
https://bugzilla.novell.com/564441
https://bugzilla.novell.com/565030
https://bugzilla.novell.com/574938
https://bugzilla.novell.com/577402
https://bugzilla.novell.com/601704
https://bugzilla.novell.com/654649
https://bugzilla.novell.com/657402
https://bugzilla.novell.com/668194
https://bugzilla.novell.com/675052
(
Log in to post comments)