Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1833-1] New dhcp3 packages fix arbitrary code execution

    From Florian Weimer@1:229/2 to All on Tue Jul 14 21:40:13 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1833-1 [email protected] http://www.debian.org/security/ Florian Weimer
    July 14, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : dhcp3
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2009-0692 CVE-2009-1892
    CERT advisory : VU#410676

    Several remote vulnerabilities have been discovered in ISC's DHCP implementation:

    It was discovered that dhclient does not properly handle overlong
    subnet mask options, leading to a stack-based buffer overflow and
    possible arbitrary code execution. (CVE-2009-0692)

    Christoph Biedl discovered that the DHCP server may terminate when
    receiving certain well-formed DHCP requests, provided that the server configuration mixes host definitions using "dhcp-client-identifier"
    and "hardware ethernet". This vulnerability only affects the lenny
    versions of dhcp3-server and dhcp3-server-ldap. (CVE-2009-1892)

    For the old stable distribution (etch), these problems have been fixed
    in version 3.0.4-13+etch2.

    For the stable distribution (lenny), this problem has been fixed in
    version 3.1.1-6+lenny2.

    For the unstable distribution (sid), these problems will be fixed
    soon.

    We recommend that you upgrade your dhcp3 packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3_3.0.4-13+etch2.diff.gz
    Size/MD5 checksum: 116721 6d49a9fb6b0617aba87cd90abef5bd57
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3_3.0.4.orig.tar.gz
    Size/MD5 checksum: 721450 aeb916fbb50edc320f142cd6a74cb48c
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3_3.0.4-13+etch2.dsc
    Size/MD5 checksum: 1077 50aac538f9bb0e11e878758d754b1e14

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-dev_3.0.4-13+etch2_alpha.deb
    Size/MD5 checksum: 157948 502301a6539a30b14cd2d6c8fb1bd032
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-relay_3.0.4-13+etch2_alpha.deb
    Size/MD5 checksum: 113528 c89f3dfd91bbb2d8850359b78f5eae66
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client-udeb_3.0.4-13+etch2_alpha.udeb
    Size/MD5 checksum: 192724 a4b5cab9e6f14ad9a80bef648435b86c
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.0.4-13+etch2_alpha.deb
    Size/MD5 checksum: 240720 48996d54bf9d3fbae7d0a4f2b0e76224
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-common_3.0.4-13+etch2_alpha.deb
    Size/MD5 checksum: 304078 2e58f7af0c23b07b81b7e88031ec22b1
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.0.4-13+etch2_alpha.deb
    Size/MD5 checksum: 346552 96169b1056055a13cbfb13fb8f73b061

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client-udeb_3.0.4-13+etch2_amd64.udeb
    Size/MD5 checksum: 174734 3de2c8f75f8d6df63870c2d9638c8ae6
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-common_3.0.4-13+etch2_amd64.deb
    Size/MD5 checksum: 287422 052994dc5544eacac9b22837bba47660
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.0.4-13+etch2_amd64.deb
    Size/MD5 checksum: 222104 185470021c69635074e4d09a05275f49
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-dev_3.0.4-13+etch2_amd64.deb
    Size/MD5 checksum: 131134 33fbb0278c39d36b2a0dd3819e192493
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.0.4-13+etch2_amd64.deb
    Size/MD5 checksum: 321874 e3ce73d54b47a930e440626672fcd521
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-relay_3.0.4-13+etch2_amd64.deb
    Size/MD5 checksum: 103610 04e95fd257de2ca592e09cf8927b9c37

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-relay_3.0.4-13+etch2_arm.deb
    Size/MD5 checksum: 99498 8098ab4856d359049538213ec0fa4a75
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client-udeb_3.0.4-13+etch2_arm.udeb
    Size/MD5 checksum: 167040 21fcc83a87ed431f9d03b0479b522dd2
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-common_3.0.4-13+etch2_arm.deb
    Size/MD5 checksum: 280430 9355307446248854bffbe49a2120d450
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.0.4-13+etch2_arm.deb
    Size/MD5 checksum: 215172 0ab20469ee9fe1ccf05bfe40b68bc2d7
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-dev_3.0.4-13+etch2_arm.deb
    Size/MD5 checksum: 123860 2b69130163d2cb83009710081a5be3ea
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.0.4-13+etch2_arm.deb
    Size/MD5 checksum: 314402 191cff362f2ceb557495d037aa2310c8

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-relay_3.0.4-13+etch2_hppa.deb
    Size/MD5 checksum: 103994 3cbfc2d7eea1de9bf64f84d31889bf75
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client-udeb_3.0.4-13+etch2_hppa.udeb
    Size/MD5 checksum: 171728 68bc286a4261035d72bbb1a63eb08dd9
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.0.4-13+etch2_hppa.deb
    Size/MD5 checksum: 219790 b8e006bf59ac068513e4bb35c4c96d2d
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-dev_3.0.4-13+etch2_hppa.deb
    Size/MD5 checksum: 139516 ee6ad7d1fd911b98cd40290823cdd50d
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.0.4-13+etch2_hppa.deb
    Size/MD5 checksum: 319134 d36a40e22c468e76386b2ab6befd8424
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-common_3.0.4-13+etch2_hppa.deb
    Size/MD5 checksum: 285302 09641cca4ba379d61c1dca0fbde543fb

    i386 architecture (Intel ia32)


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
    • Michal Wronka
      Thu Jun 4 23:19:58 2026
      from Wroclaw, Poland via Telnet
    • Michal Wronka
      Thu Jun 4 23:17:20 2026
      from Wroclaw, Poland via SSH
    • Michal Wronka
      Thu Jun 4 23:13:51 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 714
    Nodes: 16 (2 / 14)
    Uptime: 142:14:55
    Calls: 12,088
    Calls today: 1
    Files: 14,998
    Messages: 6,517,451

© >>> Magnum BBS <<<, 2026