Scientific Linux alert SL-dhcp-20111214 (dhcp)
From: | riehecky@fnal.gov | |
To: | scientific-linux-errata@fnal.gov | |
Subject: | Security ERRATA Moderate: dhcp on SL6.x i386/x86_64 | |
Date: | Thu, 15 Dec 2011 15:24:47 -0600 | |
Message-ID: | <201112152124.pBFLOlPA011362@fefmon2.fnal.gov> |
Synopsis: Moderate: dhcp security update Issue Date: 2011-12-14 CVE Numbers: CVE-2011-4539 The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows individual devices on an IP network to get their own network configuration information, including an IP address, a subnet mask, and a broadcast address. A denial of service flaw was found in the way the dhcpd daemon handled DHCP request packets when regular expression matching was used in "/etc/dhcp/dhcpd.conf". A remote attacker could use this flaw to crash dhcpd. (CVE-2011-4539) Users of DHCP should upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, all DHCP servers will be restarted automatically. SL6: i386 dhclient-4.1.1-25.P1.el6_2.1.i686.rpm dhcp-4.1.1-25.P1.el6_2.1.i686.rpm dhcp-common-4.1.1-25.P1.el6_2.1.i686.rpm dhcp-debuginfo-4.1.1-25.P1.el6_2.1.i686.rpm dhcp-devel-4.1.1-25.P1.el6_2.1.i686.rpm x86_64 dhclient-4.1.1-25.P1.el6_2.1.x86_64.rpm dhcp-4.1.1-25.P1.el6_2.1.x86_64.rpm dhcp-common-4.1.1-25.P1.el6_2.1.x86_64.rpm dhcp-debuginfo-4.1.1-25.P1.el6_2.1.i686.rpm dhcp-debuginfo-4.1.1-25.P1.el6_2.1.x86_64.rpm dhcp-devel-4.1.1-25.P1.el6_2.1.i686.rpm dhcp-devel-4.1.1-25.P1.el6_2.1.x86_64.rpm - Scientific Linux Development Team