=========================================================================Ubuntu Security Notice USN-1309-1
December 15, 2011

isc-dhcp vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04

Summary:

DHCP could be made to crash if it received specially crafted network
traffic.

Software Description:
- isc-dhcp: DHCP server and client

Details:

It was discovered that the DHCP server incorrectly handled certain
malformed packets when configured to evaluate regular expressions. A remote
attacker could use this issue to cause DHCP to crash, resulting in a denial
of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  isc-dhcp-server                 4.1.1-P1-17ubuntu10.1

Ubuntu 11.04:
  isc-dhcp-server                 4.1.1-P1-15ubuntu9.3

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-1309-1
  CVE-2011-4539

Package Information:
  https://launchpad.net/ubuntu/+source/isc-dhcp/4.1.1-P1-17ubuntu10.1
  https://launchpad.net/ubuntu/+source/isc-dhcp/4.1.1-P1-15ubuntu9.3


Ubuntu 1309-1: DHCP vulnerability

December 15, 2011
DHCP could be made to crash if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: isc-dhcp-server 4.1.1-P1-17ubuntu10.1 Ubuntu 11.04: isc-dhcp-server 4.1.1-P1-15ubuntu9.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1309-1

CVE-2011-4539

Severity
December 15, 2011

Package Information

https://launchpad.net/ubuntu/+source/isc-dhcp/4.1.1-P1-17ubuntu10.1 https://launchpad.net/ubuntu/+source/isc-dhcp/4.1.1-P1-15ubuntu9.3

Related News