Twenty Year Anniversary

Mandriva Linux Security Advisory 2012-115

Mandriva Linux Security Advisory 2012-115
Posted Jul 27, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-115 - An unexpected client identifier parameter can cause the ISC DHCP daemon to segmentation fault when running in DHCPv6 mode, resulting in a denial of service to further client requests. In order to exploit this condition, an attacker must be able to send requests to the DHCP server. An error in the handling of malformed client identifiers can cause a DHCP server running affected versions to enter a state where further client requests are not processed and the server process loops endlessly, consuming all available CPU cycles. Under normal circumstances this condition should not be triggered, but a non-conforming or malicious client could deliberately trigger it in a vulnerable server. In order to exploit this condition an attacker must be able to send requests to the DHCP server. Two memory leaks have been found and fixed in ISC DHCP. The updated packages have been upgraded to the latest version which is not affected by these issues.

tags | advisory, denial of service, memory leak
systems | linux, mandriva
advisories | CVE-2012-3570, CVE-2012-3571, CVE-2012-3954
MD5 | b8bec5432648e11ee761ae836102755b

Mandriva Linux Security Advisory 2012-115

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2012:115
http://www.mandriva.com/security/
_______________________________________________________________________

Package : dhcp
Date : July 26, 2012
Affected: 2011.
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been discovered and corrected in ISC DHCP:

An unexpected client identifier parameter can cause the ISC DHCP
daemon to segmentation fault when running in DHCPv6 mode, resulting
in a denial of service to further client requests. In order to exploit
this condition, an attacker must be able to send requests to the DHCP
server (CVE-2012-3570

An error in the handling of malformed client identifiers can cause
a DHCP server running affected versions (see Impact) to enter a
state where further client requests are not processed and the server
process loops endlessly, consuming all available CPU cycles. Under
normal circumstances this condition should not be triggered, but a
non-conforming or malicious client could deliberately trigger it in
a vulnerable server. In order to exploit this condition an attacker
must be able to send requests to the DHCP server (CVE-2012-3571

Two memory leaks have been found and fixed in ISC DHCP. Both are
reproducible when running in DHCPv6 mode (with the -6 command-line
argument.) The first leak is confirmed to only affect servers
operating in DHCPv6 mode, but based on initial code analysis the
second may theoretically affect DHCPv4 servers (though this has not
been demonstrated.) (CVE-2012-3954).

The updated packages have been upgraded to the latest version
(4.2.4-P1) which is not affected by these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3570
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3571
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3954
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2011:
5153e3eb1b4ceca9f800544d13ef6872 2011/i586/dhcp-client-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
8c6117c838ec86e12abe5ea1efa12f85 2011/i586/dhcp-common-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
03dd3ee3fe46a4bc255a20bc0a3f4edd 2011/i586/dhcp-devel-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
e6fb5efee36e445626e3e52314cb24e1 2011/i586/dhcp-doc-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
4da38e33e8542ae24e59f475a216dc88 2011/i586/dhcp-relay-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
af313c55824cd839740cd03556b43650 2011/i586/dhcp-server-4.2.4-0.P1.1.1-mdv2011.0.i586.rpm
c6766b7bfe76fbbbfe19df2a08863c47 2011/SRPMS/dhcp-4.2.4-0.P1.1.1.src.rpm

Mandriva Linux 2011/X86_64:
d59247271566158ed3ce91748e8bd244 2011/x86_64/dhcp-client-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
66e0771c5304de4550560bd39aa40f77 2011/x86_64/dhcp-common-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
37d678da37bb3b21a14a1e68619342de 2011/x86_64/dhcp-devel-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
5311a79668ab721cd829061f48dbbf39 2011/x86_64/dhcp-doc-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
5c59c00623d6b3a3a2130a5a467a9d33 2011/x86_64/dhcp-relay-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
cc93817435d581230d1e7fcee425abb3 2011/x86_64/dhcp-server-4.2.4-0.P1.1.1-mdv2011.0.x86_64.rpm
c6766b7bfe76fbbbfe19df2a08863c47 2011/SRPMS/dhcp-4.2.4-0.P1.1.1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iD8DBQFQEUxWmqjQ0CJFipgRAnMbAKDbViRMHizm7ES7BCmCya4K53J1BQCeLl+G
mS5VX3nUx8CROAYnnG6xQl8=
=EANl
-----END PGP SIGNATURE-----

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

December 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    11 Files
  • 2
    Dec 2nd
    1 Files
  • 3
    Dec 3rd
    18 Files
  • 4
    Dec 4th
    40 Files
  • 5
    Dec 5th
    16 Files
  • 6
    Dec 6th
    50 Files
  • 7
    Dec 7th
    12 Files
  • 8
    Dec 8th
    1 Files
  • 9
    Dec 9th
    1 Files
  • 10
    Dec 10th
    15 Files
  • 11
    Dec 11th
    30 Files
  • 12
    Dec 12th
    25 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close