Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1833-2] New dhcp3 packages fix arbitrary code execution

    From Florian Weimer@1:229/2 to All on Tue Aug 25 22:00:14 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1833-2 [email protected] http://www.debian.org/security/ Florian Weimer
    August 25, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : dhcp3
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2009-0692 CVE-2009-1892
    CERT advisory : VU#410676

    The previous dhcp3 update (DSA-1833-1) did not properly apply the
    required changes to the stable (lenny) version. The old stable (etch)
    version is not affected by this problem.

    The original advisory description follows.

    Several remote vulnerabilities have been discovered in ISC's DHCP implementation:

    It was discovered that dhclient does not properly handle overlong
    subnet mask options, leading to a stack-based buffer overflow and
    possible arbitrary code execution. (CVE-2009-0692)

    Christoph Biedl discovered that the DHCP server may terminate when
    receiving certain well-formed DHCP requests, provided that the server configuration mixes host definitions using "dhcp-client-identifier"
    and "hardware ethernet". This vulnerability only affects the lenny
    versions of dhcp3-server and dhcp3-server-ldap. (CVE-2009-1892)

    For the stable distribution (lenny), this problem has been fixed in
    version 3.1.1-6+lenny3.

    We recommend that you upgrade your dhcp3 packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3_3.1.1.orig.tar.gz
    Size/MD5 checksum: 798228 fcc19330a9c3a0efb5620409214652a9
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3_3.1.1-6+lenny3.dsc
    Size/MD5 checksum: 1488 b884753ce46061cc6e0e6a783d7c24a3
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3_3.1.1-6+lenny3.diff.gz
    Size/MD5 checksum: 128921 178f7799fbe3e8fb5a0472a8060bebf7

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp-client_3.1.1-6+lenny3_all.deb
    Size/MD5 checksum: 23010 e772483a84fdca84407e39556188a13e

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-dev_3.1.1-6+lenny3_alpha.deb
    Size/MD5 checksum: 148302 296381030181bf29e5185823472c34c7
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server-ldap_3.1.1-6+lenny3_alpha.deb
    Size/MD5 checksum: 348542 910f44119d0cbcefdfdb0496b72f75c0
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.1.1-6+lenny3_alpha.deb
    Size/MD5 checksum: 272004 63e37fc50ae798ad86713ff354f5b996
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.1.1-6+lenny3_alpha.deb
    Size/MD5 checksum: 394460 a77802ce027f350aed83be710c92fa9f
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client-udeb_3.1.1-6+lenny3_alpha.udeb
    Size/MD5 checksum: 215132 ea9207b439e373b7cda0633600fc2a66
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-relay_3.1.1-6+lenny3_alpha.deb
    Size/MD5 checksum: 127514 f1287179244c1684b1a892c187624425
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-common_3.1.1-6+lenny3_alpha.deb
    Size/MD5 checksum: 333782 713d3ad0235144a0537d747a66766b6a

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-common_3.1.1-6+lenny3_amd64.deb
    Size/MD5 checksum: 310356 6fb09a20cce949a6edd1a9a628863a2d
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-relay_3.1.1-6+lenny3_amd64.deb
    Size/MD5 checksum: 114266 bb511a3be6b474ba6233a00bd70d52b3
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client-udeb_3.1.1-6+lenny3_amd64.udeb
    Size/MD5 checksum: 188422 f2aaca0e2a93c0b3647d6cebc2dc515e
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.1.1-6+lenny3_amd64.deb
    Size/MD5 checksum: 358418 15b92a206a5f782b91ef21a1cb89d8c1
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.1.1-6+lenny3_amd64.deb
    Size/MD5 checksum: 245246 22f8d4e550561f67ac9145e114281d30
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server-ldap_3.1.1-6+lenny3_amd64.deb
    Size/MD5 checksum: 313224 2033f60c749a3e71631a5b153a77ae27
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-dev_3.1.1-6+lenny3_amd64.deb
    Size/MD5 checksum: 120442 f86b93961879963e2ea5dc0c5f2d344c

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.1.1-6+lenny3_arm.deb
    Size/MD5 checksum: 226592 ddba5071d36b331c5a001b67a1b94410
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server-ldap_3.1.1-6+lenny3_arm.deb
    Size/MD5 checksum: 291194 4673741acf27ce06150203ea2cfde77f
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-relay_3.1.1-6+lenny3_arm.deb
    Size/MD5 checksum: 103716 cfa5568781f496e02e490ad803b79acc
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.1.1-6+lenny3_arm.deb
    Size/MD5 checksum: 336408 56415a0df425eace6189f47585a63c01
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-dev_3.1.1-6+lenny3_arm.deb
    Size/MD5 checksum: 108910 efb3c5019520090a189212af9b6dcf3d
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-common_3.1.1-6+lenny3_arm.deb
    Size/MD5 checksum: 292858 3d1d50251c7953847178a888e6cd91cf
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client-udeb_3.1.1-6+lenny3_arm.udeb
    Size/MD5 checksum: 170066 18a05aa4dfe765c6cc3f99b31e77ecac

    armel architecture (ARM EABI)

    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-client_3.1.1-6+lenny3_armel.deb
    Size/MD5 checksum: 227670 41fc7a60258569b01280b594d6293264
    http://security.debian.org/pool/updates/main/d/dhcp3/dhcp3-server_3.1.1-6+lenny3_armel.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Tue Jun 9 11:18:15 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (3 / 13)
    Uptime: 43:06:55
    Calls: 12,111
    Calls today: 2
    Files: 15,008
    Messages: 6,518,438

© >>> Magnum BBS <<<, 2026