Debian alert DLA-2003-1 (isc-dhcp)
From: | Thorsten Alteholz <debian@alteholz.de> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 2003-1] isc-dhcp security update | |
Date: | Sun, 24 Nov 2019 19:13:27 +0100 (CET) | |
Message-ID: | <alpine.DEB.2.20.1911241910550.26284@jupiter.server.alteholz.net> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : isc-dhcp Version : 4.3.1-6+deb8u4 CVE ID : CVE-2016-2774 An issue has been found in isc-dhcp, a server for automatic IP address assignment. The number of simultaneous open TCP connections to OMAPI port of the server has to be limited to 200 in order to avoid a denial of service. For Debian 8 "Jessie", this problem has been fixed in version 4.3.1-6+deb8u4. We recommend that you upgrade your isc-dhcp packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl3ayEdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7 WEdXTA//T/veZkM6LzLdfuP66FlwVTz5Gk1tShSaDGQxb35WV1DnwZ/uNzec+WVf dnSNKckNeZhjMvDzvHb33qf94KQjyWUx+fXwv7Q3YSB4NpoD+TQJh+2EOuqRKxsu lJVx7q6XXEwvnvCCGI0kPGzURLLNrPH9J6KHUr48kZHsudZYBZfGCJvFl1v+bkBI hwghvKe/cLzawO08bwdl8cPOLqegLeX9oEJ4/75OGJi+WagcWhc3xaGFVnhJqWdE vWPJqE27lG4R1xpd3+M07ykWf8JKTU37zb0PlSEgJDpOpBSoTqpck9EnD2iV/TKq alwt+ddb0nib6uB38HWFfvcSjuF0oWYCKqff0sHQKvHx+XLCcpMuKXbKyX1y4cZU m4Y/QEWxMzAnBDBjJuEBomXBWpdNDtMi7COw8TaDAeeVeAF1aliMvCWTUPZkIpEO 6FBiIvWU5fBxZ+aNgcw/HFLIcJ06Y8AdaccyLIEuyzLRXEeu2wE+1vXsOCd8o/v1 jfKMDAovUU3kcgDrlPS4dfiT4ePXTl6GQUMS19BZWh8ml5QEdmbGvebC0Sdxhgl4 VMep3bSRmZ8jYvJiQACZpBQRvB/YOHy2eyRpPLcbU4YB3ICkXjRnZ/OjtLpiYwjz iSqmuOcwWg0DxJsrHrqmSB2ZzgOsdcrhh41SKzRiU+/JQDs9cco= =wBo9 -----END PGP SIGNATURE-----