Package        : pump
Version        : 0.8.24-7+deb8u1
Debian Bug     : #933674

It was discovered that there was an arbitrary code execution
vulnerability in the pump BOOTP and DHCP client.

When copying the body of the server response, the ethernet packet
length could be forged leading to being able to overwrite up to
"ETH_FRAME_LEN - sizeof(*ipHdr) - sizeof(*udpHdr) - sizeof(*bresp)"
bytes of stack memory.

Thanks to  for the report and patch.

For Debian 8 "Jessie", this issue has been fixed in pump version
0.8.24-7+deb8u1.

We recommend that you upgrade your pump packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1908-1: pump security update

September 2, 2019
It was discovered that there was an arbitrary code execution vulnerability in the pump BOOTP and DHCP client

Summary

Thanks to for the report and patch.

For Debian 8 "Jessie", this issue has been fixed in pump version
0.8.24-7+deb8u1.

We recommend that you upgrade your pump packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : pump
Version : 0.8.24-7+deb8u1
Debian Bug : #933674

Related News