Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Dhcp: Buffer Overflow
Posted by Benjamin D. Thomas
malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
--==============14920936=Content-Type: multipart/alternative; boundary 1636c5adf4895438046f6f8e79
--001636c5adf4895438046f6f8e79
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-107 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-07-24
Severity: 3
Type: Local
------------------------------------------------------------------------
Summary
======
A vulnerability has been reported in ISC DHCP, which can be exploited by
malicious people to cause a DoS (Denial of Service) and potentially
compromise a user's system.
Description
==========
The vulnerability is caused due to a boundary error within the
"script_write_params()" function in client/dhclient.c and can be
exploited to cause a stack-based buffer overflow by sending an overly
long subnet-mask option.
Successful exploitation may allow execution of arbitrary code with
"root" privileges, but requires that dhclient processes a specially
crafted response from a malicious DHCP server
Affected packages:
Pardus 2008:
dhcp, all before 3.1.2_p1-16-3
Resolution
=========
There are update(s) for dhcp. You can update them via Package Manager or
with a single command from console:
pisi up dhcp
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id476
* http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0692
* http://secunia.com/advisories/35785