The previous dhcp3 update (DSA-1833-1) did not properly apply the
required changes to the stable (lenny) version. The old stable (etch)
version is not affected by this problem.
The original advisory description follows.
Several remote vulnerabilities have been discovered in ISC's DHCP
implementation:
It was discovered that dhclient does not properly handle overlong
subnet mask options, leading to a stack-based buffer overflow and
possible arbitrary code execution. (CVE-2009-0692)
Christoph Biedl discovered that the DHCP server may terminate when
receiving certain well-formed DHCP requests, provided that the server
configuration mixes host definitions using "dhcp-client-identifier"
and "hardware ethernet". This vulnerability only affects the lenny
versions of dhcp3-server and dhcp3-server-ldap. (CVE-2009-1892)
For the stable distribution (lenny), this problem has been fixed in
version 3.1.1-6+lenny3.
We recommend that you upgrade your dhcp3 packages.
Upgrade instructions
- --------------------
wget...
Get the latest Linux and open source security news straight to your inbox.