ISC DHCP: dhcpclient Remote execution of arbitrary code
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200907-12 / dhcp |
| Release Date |
July 14, 2009 |
| Latest Revision |
July 14, 2009: 01 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/dhcp |
<
3.1.1-r1 |
>=
3.1.1-r1 |
All supported architectures
|
Related bugreports:
#277729
Synopsis
A buffer overflow in dhclient as included in the ISC DHCP implementation
allows for the remote execution of arbitrary code with root privileges.
2.
Impact Information
Background
ISC DHCP is the reference implementation of the Dynamic Host
Configuration Protocol as specified in RFC 2131.
Description
The Mandriva Linux Engineering Team has reported a stack-based buffer
overflow in the subnet-mask handling of dhclient.
Impact
A remote attacker might set up a rogue DHCP server in a victim's local
network, possibly leading to the execution of arbitrary code with root
privileges.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All ISC DHCP users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/dhcp-3.1.1-r1"
|
4.
References
|