GLSA: dhcp

From: Daniel Ahlberg (alizat_private)
Date: Fri Jan 17 2003 - 02:45:56 PST

  • Next message: fabio miotti: "certificate x.509 and outlook express 6"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200301-10
    - - --------------------------------------------------------------------
    
    PACKAGE : dhcp
    SUMMARY : buffer overflow
    DATE    : 2003-01-17 10:01 UTC
    EXPLOIT : remote
    
    - - --------------------------------------------------------------------
    
    - From advisory :
    
    "The Internet Software Consortium (ISC) has discovered several buffer
    overflow vulnerabilities in their implementation of DHCP (ISC DHCPD).
    These vulnerabilities may allow remote attackers to execute arbitrary
    code on affected systems.  At this time, we are not aware of any
    exploits."
    
    Read the full advisory at
    http://www.cert.org/advisories/CA-2003-01.html
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    net-misc/dhcp upgrade to dhcp-3.0_p2 as follows:
    
    emerge sync
    emerge -u dhcp
    emerge clean
    
    - - --------------------------------------------------------------------
    alizat_private - GnuPG key is available at www.gentoo.org/~aliz
    lostlogicat_private
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)
    
    iD8DBQE+J97gfT7nyhUpoZMRAvWAAKCmwJ9SZ9BHqLlVSnpU6uuJdIGR+ACfXpTw
    ZFnl0fBTQKE3c0ymwNUdQT8=
    =Ukux
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Tue Jan 21 2003 - 19:08:39 PST