| From: |
| opensuse-security@opensuse.org |
| To: |
| opensuse-updates@opensuse.org |
| Subject: |
| openSUSE-SU-2011:0385-1 (important): dhcpcd security update |
| Date: |
| Thu, 21 Apr 2011 16:08:07 +0200 (CEST) |
| Message-ID: |
| <20110421140808.0E7503223E@maintenance.suse.de> |
| Archive-link: |
| Article, Thread
|
openSUSE Security Update: dhcpcd security update
______________________________________________________________________________
Announcement ID: openSUSE-SU-2011:0385-1
Rating: important
References: #675052 #687850
Cross-References: CVE-2011-0996
Affected Products:
openSUSE 11.4
openSUSE 11.3
openSUSE 11.2
______________________________________________________________________________
An update that solves one vulnerability and has one errata
is now available.
Description:
This update fixes the following security issue:
A rogue DHCP server could instruct clients to use a host
name that contains shell meta characters. Since many
scripts in the system do not expect unusal characters in
the system's host name the DHCP client needs to sanitize
the host name offered by the server (CVE-2011-0996).
Note this update is actually just a re-release of the
previous one. The security fix made dhcpcd crash if the
DHCP server sent a SIP option that was not decodable. This
update also allows spaces in the domain name option again
as some DHCP servers abuse the option as DNS search list.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.4:
zypper in -t patch dhcpcd-4412
- openSUSE 11.3:
zypper in -t patch dhcpcd-4411
- openSUSE 11.2:
zypper in -t patch dhcpcd-4410
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.4 (i586 x86_64):
dhcpcd-3.2.3-66.69.1
- openSUSE 11.3 (i586 x86_64):
dhcpcd-3.2.3-61.66.1
- openSUSE 11.2 (i586 x86_64):
dhcpcd-3.2.3-47.66.1
References:
http://support.novell.com/security/cve/CVE-2011-0996.html
https://bugzilla.novell.com/675052
https://bugzilla.novell.com/687850
(
Log in to post comments)