| Red Hat, Inc. Security
Advisory |
||
| Package | pump | |
| Synopsis | Bugs fixed in pump (DHCP client) [CORRECTION] | |
| Advisory ID | RHSA-1999:027-02 | |
| Issue Date | 1999-08-11 | |
| Updated on | 1999-08-14 | |
| Keywords | pump DHCP RoadRunner @Home | |
|
1. Topic: This is a correction to our previous announcement, which did not mention the security bug that is fixed in pump 0.7.0.
2. Bug IDs fixed:
3. Relevant releases/architectures:
4. Obsoleted by:
5. Conflicts with:
6. RPMs required: Intel:
pump-0.7.0-
1.i386.rpm Alpha:
pump-0.7.0-
1.alpha.rpm SPARC:
pump-0.7.0-
1.sparc.rpm Source:
pump-0.7.0- 1.src.rpm
Architecture neutral:
7. Problem description: o Some (broken) servers did not return server address properly; in these cases, pump now reuses the broadcast address. o There was a security hole with the potential for a remote root exploit in certain configurations where DHCP is used on public networks
8. Solution: rpm -Uvh filename where filename is the name of the RPM.
9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- a93c710c0ce18e79b3dd33d268ae7752 i386/pump-0.7.0-1.i386.rpm 53df0de539645b34ad93272f3b4e6d97 alpha/pump-0.7.0-1.alpha.rpm d56bac8b659b353894092869782d59cc sparc/pump-0.7.0-1.sparc.rpm 2f18a5c39cdd327e0406df1ab5308549 SRPMS/pump-0.7.0-1.src.rpmThese packages are also PGP signed by Red Hat Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig filename If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nopgp filename
10. References: |
||
For each RPM for your particular architecture, run:
rpm -Uvh filename
where filename is the name of the RPM.
9. Verification:
MD5 sum Package Name
a93c710c0ce18e79b3dd33d268ae7752 i386/pump-0.7.0-1.i386.rpm
53df0de539645b34ad93272f3b4e6d97 alpha/pump-0.7.0-1.alpha.rpm
d56bac8b659b353894092869782d59cc sparc/pump-0.7.0-1.sparc.rpm
2f18a5c39cdd327e0406df1ab5308549 SRPMS/pump-0.7.0-1.src.rpm
These packages are also PGP signed by Red Hat Inc. for security. Our
key is available at:
You can verify each package with the following command:
rpm --checksig filename
If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
rpm --checksig --nopgp filename
Red Hat Linux 6.0, all architectures
4. Obsoleted by:
None
5. Conflicts with:
None
6. RPMs required:
Intel:
pump-0.7.0-
1.i386.rpm
Alpha:
pump-0.7.0-
1.alpha.rpm
SPARC:
pump-0.7.0-
1.sparc.rpm
Source:
pump-0.7.0-
1.src.rpm
Architecture neutral:
client) [CORRECTION]
ID
Date
on
@Home
Get the latest Linux and open source security news straight to your inbox.