FS#15515 - [dhclient] DHCP Stack Overflow in 'dhclient' script_write_params()

Attached to Project: Arch Linux
Opened by Roman Kyrylych (Romashka) - Wednesday, 15 July 2009, 08:26 GMT
Last edited by Isenmann Daniel (ise) - Sunday, 19 July 2009, 18:09 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Isenmann Daniel (ise)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

Description:
ISC dhclient has a stack overflow vulnerability which makes it theoretically possible for a rogue DHCP server to execute arbitrary commands as root on the affected system through stack return subversion.

Additional info:
https://www.isc.org/node/468
http://www.kb.cert.org/vuls/id/410676

Solution:
Upgrade to 4.1.0p1, 4.0.1p1, or 3.1.2p1
(FYI, I think Debian applied some patch instead of upgrading)
This task depends upon

Closed by  Isenmann Daniel (ise)
Sunday, 19 July 2009, 18:09 GMT
Reason for closing:  Fixed
Additional comments about closing:  Fixed in version 3.1.2p1 in testing repo. Please test the release.

Loading...