LWN.net Logo

DHCP remotely exploitable format string vulnerability

Package(s):dhcp/dhcp-server dhcp CVE #(s):
Created:May 21, 2002 Updated:June 20, 2002
Description: The May 8, 2000 release of ISC DHCP 3.0p1 fixes this serious vulnerability in ISC DHCPD 3.0 to 3.0.1rc8 inclusive.

We encourage dhcp users to upgrade, disable dhcp or, at a minimum, consider using ingress filtering as described in the CERT advisory. (First LWN report: May 16).

Note: Distributions which use version 2 of ISC DHCP, such as Red Hat Linux, are not vulnerable.

Alerts:
SCO Group CSSA-2002-028.0 2002-06-19
Mandrake MDKSA-2002:037-1 2002-05-30
SuSE SuSE-SA:2002:019 2002-05-22
Mandrake MDKSA-2002:037 2002-05-29
Conectiva CLA-2002:483 2002-05-09

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds