Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Debian DSA-2498-1: Severe Dhcpcd Stack Overflow Vulnerability Alert

debian
Calendar Grey June 24, 2012
Debian Logo
A buffer overflow issue in dhcpcd may result in service interruption and the possibility of remote code execution. It is advised to implement updates promptly.
It was discovered that dhcpcd, a DHCP client, was vulnerable to a stack overflow

Summary

It was discovered that dhcpcd, a DHCP client, was vulnerable to a stack
overflow. A malformed DHCP message could crash the client, causing a denial of
service, and potentially remote code execution through properly designed
malicous DHCP packets.

For the stable distribution (squeeze), this problem has been fixed in
version 1:3.2.3-5+squeeze1.

For the testing distribution (wheezy), this problem has been fixed in
version 1:3.2.3-11.

For the unstable distribution (sid), this problem has been fixed in
version 1:3.2.3-11.

We recommend that you upgrade your dhcpcd package.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: dhcpcd
CVE ID: CVE-2012-2152

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here