LWN.net Logo

Scientific Linux alert SL-dhcp-20120803 (dhcp)

From:  riehecky@fnal.gov
To:  scientific-linux-errata@fnal.gov
Subject:  Security ERRATA Moderate: dhcp on SL5.x i386/x86_64
Date:  Fri, 3 Aug 2012 11:29:33 -0500
Message-ID:  <201208031629.q73GTXdU018621@fefmon2.fnal.gov>
Archive-link:  Article, Thread

Synopsis: Moderate: dhcp security update Issue Date: 2012-08-03 CVE Numbers: CVE-2012-3571 The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows individual devices on an IP network to get their own network configuration information, including an IP address, a subnet mask, and a broadcast address. A denial of service flaw was found in the way the dhcpd daemon handled zero-length client identifiers. A remote attacker could use this flaw to send a specially-crafted request to dhcpd, possibly causing it to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2012-3571) Users of DHCP should upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, all DHCP servers will be restarted automatically. SL5: i386 dhclient-3.0.5-31.el5_8.1.i386.rpm dhcp-3.0.5-31.el5_8.1.i386.rpm dhcp-debuginfo-3.0.5-31.el5_8.1.i386.rpm dhcp-devel-3.0.5-31.el5_8.1.i386.rpm libdhcp4client-3.0.5-31.el5_8.1.i386.rpm libdhcp4client-devel-3.0.5-31.el5_8.1.i386.rpm x86_64 dhclient-3.0.5-31.el5_8.1.x86_64.rpm dhcp-3.0.5-31.el5_8.1.x86_64.rpm dhcp-debuginfo-3.0.5-31.el5_8.1.i386.rpm dhcp-debuginfo-3.0.5-31.el5_8.1.x86_64.rpm dhcp-devel-3.0.5-31.el5_8.1.i386.rpm dhcp-devel-3.0.5-31.el5_8.1.x86_64.rpm libdhcp4client-3.0.5-31.el5_8.1.i386.rpm libdhcp4client-3.0.5-31.el5_8.1.x86_64.rpm libdhcp4client-devel-3.0.5-31.el5_8.1.i386.rpm libdhcp4client-devel-3.0.5-31.el5_8.1.x86_64.rpm - Scientific Linux Development Team


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds