Twenty Year Anniversary

Mandriva Linux Security Advisory 2012-115

Mandriva Linux Security Advisory 2012-115
Posted Jul 27, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-115 - An unexpected client identifier parameter can cause the ISC DHCP daemon to segmentation fault when running in DHCPv6 mode, resulting in a denial of service to further client requests. In order to exploit this condition, an attacker must be able to send requests to the DHCP server. An error in the handling of malformed client identifiers can cause a DHCP server running affected versions to enter a state where further client requests are not processed and the server process loops endlessly, consuming all available CPU cycles. Under normal circumstances this condition should not be triggered, but a non-conforming or malicious client could deliberately trigger it in a vulnerable server. In order to exploit this condition an attacker must be able to send requests to the DHCP server. Two memory leaks have been found and fixed in ISC DHCP. The updated packages have been upgraded to the latest version which is not affected by these issues.

tags | advisory, denial of service, memory leak
systems | linux, mandriva
advisories | CVE-2012-3570, CVE-2012-3571, CVE-2012-3954
MD5 | b8bec5432648e11ee761ae836102755b

Mandriva Linux Security Advisory 2012-115

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2012:115
http://www.mandriva.com/security/
_______________________________________________________________________

Package : dhcp
Date : July 26, 2012
Affected: 2011.
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been discovered and corrected in ISC DHCP:

An unexpected client identifier parameter can cause the ISC DHCP
daemon to segmentation fault when running in DHCPv6 mode, resulting
in a denial of service to further client requests. In order to exploit
this condition, an attacker must be able to send requests to the DHCP
server (CVE-2012-3570

An error in the handling of malformed client identifiers can cause
a DHCP server running affected versions (see Impact) to enter a
state where further client requests are not processed and the server
process loops endlessly, consuming all available CPU cycles. Under
normal circumstances this condition should not be triggered, but a
non-conforming or malicious client could deliberately trigger it in
a vulnerable server. In order to exploit this condition an attacker
must be able to send requests to the DHCP server (CVE-2012-3571

Two memory leaks have been found and fixed in ISC DHCP. Both are
reproducible when running in DHCPv6 mode (with the -6 command-line
argument.) The first leak is confirmed to only affect servers
operating in DHCPv6 mode, but based on initial code analysis the
second may theoretically affect DHCPv4 servers (though this has not
been demonstrated.) (CVE-2012-3954).

The updated packages have been upgraded to the latest version
(4.2.4-P1) which is not affected by these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3570
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3571
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3954
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2011:
5153e3eb1b4ceca9f800544d13ef6872 2011/i586/dhcp-client-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
8c6117c838ec86e12abe5ea1efa12f85 2011/i586/dhcp-common-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
03dd3ee3fe46a4bc255a20bc0a3f4edd 2011/i586/dhcp-devel-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
e6fb5efee36e445626e3e52314cb24e1 2011/i586/dhcp-doc-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
4da38e33e8542ae24e59f475a216dc88 2011/i586/dhcp-relay-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
af313c55824cd839740cd03556b43650 2011/i586/dhcp-server-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
c6766b7bfe76fbbbfe19df2a08863c47 2011/SRPMS/dhcp-4.2.4-0.P1.1.1.src.rpm

Mandriva Linux 2011/X86_64:
d59247271566158ed3ce91748e8bd244 2011/x86_64/dhcp-client-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
66e0771c5304de4550560bd39aa40f77 2011/x86_64/dhcp-common-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
37d678da37bb3b21a14a1e68619342de 2011/x86_64/dhcp-devel-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
5311a79668ab721cd829061f48dbbf39 2011/x86_64/dhcp-doc-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
5c59c00623d6b3a3a2130a5a467a9d33 2011/x86_64/dhcp-relay-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
cc93817435d581230d1e7fcee425abb3 2011/x86_64/dhcp-server-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
c6766b7bfe76fbbbfe19df2a08863c47 2011/SRPMS/dhcp-4.2.4-0.P1.1.1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iD8DBQFQEUxWmqjQ0CJFipgRAnMbAKDbViRMHizm7ES7BCmCya4K53J1BQCeLl+G
mS5VX3nUx8CROAYnnG6xQl8=
=EANl
-----END PGP SIGNATURE-----

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

September 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    1 Files
  • 2
    Sep 2nd
    3 Files
  • 3
    Sep 3rd
    15 Files
  • 4
    Sep 4th
    15 Files
  • 5
    Sep 5th
    18 Files
  • 6
    Sep 6th
    18 Files
  • 7
    Sep 7th
    15 Files
  • 8
    Sep 8th
    2 Files
  • 9
    Sep 9th
    2 Files
  • 10
    Sep 10th
    16 Files
  • 11
    Sep 11th
    17 Files
  • 12
    Sep 12th
    15 Files
  • 13
    Sep 13th
    29 Files
  • 14
    Sep 14th
    21 Files
  • 15
    Sep 15th
    3 Files
  • 16
    Sep 16th
    1 Files
  • 17
    Sep 17th
    15 Files
  • 18
    Sep 18th
    16 Files
  • 19
    Sep 19th
    29 Files
  • 20
    Sep 20th
    18 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close