LWN.net Logo

Scientific Linux alert SL-dhcp-20120803 (dhcp)

From:  riehecky@fnal.gov
To:  scientific-linux-errata@fnal.gov
Subject:  Security ERRATA Moderate: dhcp on SL6.x i386/x86_64
Date:  Fri, 3 Aug 2012 08:32:07 -0500
Message-ID:  <201208031332.q73DW7PF031681@fefmon2.fnal.gov>
Archive-link:  Article, Thread

Synopsis: Moderate: dhcp security update Issue Date: 2012-08-03 CVE Numbers: CVE-2012-3571 CVE-2012-3954 The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows individual devices on an IP network to get their own network configuration information, including an IP address, a subnet mask, and a broadcast address. A denial of service flaw was found in the way the dhcpd daemon handled zero-length client identifiers. A remote attacker could use this flaw to send a specially-crafted request to dhcpd, possibly causing it to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2012-3571) Two memory leak flaws were found in the dhcpd daemon. A remote attacker could use these flaws to cause dhcpd to exhaust all available memory by sending a large number of DHCP requests. (CVE-2012-3954) Users of DHCP should upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, all DHCP servers will be restarted automatically. SL6: i386 dhclient-4.1.1-31.P1.el6_3.1.i686.rpm dhcp-4.1.1-31.P1.el6_3.1.i686.rpm dhcp-common-4.1.1-31.P1.el6_3.1.i686.rpm dhcp-debuginfo-4.1.1-31.P1.el6_3.1.i686.rpm dhcp-devel-4.1.1-31.P1.el6_3.1.i686.rpm x86_64 dhclient-4.1.1-31.P1.el6_3.1.x86_64.rpm dhcp-4.1.1-31.P1.el6_3.1.x86_64.rpm dhcp-common-4.1.1-31.P1.el6_3.1.x86_64.rpm dhcp-debuginfo-4.1.1-31.P1.el6_3.1.i686.rpm dhcp-debuginfo-4.1.1-31.P1.el6_3.1.x86_64.rpm dhcp-devel-4.1.1-31.P1.el6_3.1.i686.rpm dhcp-devel-4.1.1-31.P1.el6_3.1.x86_64.rpm - Scientific Linux Development Team


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds