ISC DHCPD Remote Format String Vulnerability
BID:11591
Info
ISC DHCPD Remote Format String Vulnerability
| Bugtraq ID: | 11591 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1006 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery of this vulnerability is credited to [email protected]. |
| Vulnerable: |
Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 ISC DHCPD 3.0.1 rc9 ISC DHCPD 3.0.1 rc8 ISC DHCPD 3.0.1 rc7 ISC DHCPD 3.0.1 rc6 ISC DHCPD 3.0.1 rc5 ISC DHCPD 3.0.1 rc4 ISC DHCPD 3.0.1 rc3 ISC DHCPD 3.0.1 rc2 ISC DHCPD 3.0.1 rc14 ISC DHCPD 3.0.1 rc13 ISC DHCPD 3.0.1 rc12 ISC DHCPD 3.0.1 rc11 ISC DHCPD 3.0.1 rc10 ISC DHCPD 3.0.1 rc1 ISC DHCPD 3.0 rc4 ISC DHCPD 3.0 rc12 ISC DHCPD 3.0 pl2 ISC DHCPD 3.0 pl1 ISC DHCPD 3.0 b2pl9 ISC DHCPD 3.0 b2pl23 ISC DHCPD 3.0 ISC DHCPD 2.0.pl5 |
| Not Vulnerable: |
ISC DHCPD 3.0.2rc1 |
Discussion
ISC DHCPD Remote Format String Vulnerability
A remote format string vulnerability is reported in the ISC DHCPD server package. User supplied data is logged in an unsafe fashion. Exploitation of this vulnerability may result in arbitrary code being executed by the DHCP server. Although unconfirmed it is conjectured that this issue may only be exploitable when debugging functionality is enabled.
A remote format string vulnerability is reported in the ISC DHCPD server package. User supplied data is logged in an unsafe fashion. Exploitation of this vulnerability may result in arbitrary code being executed by the DHCP server. Although unconfirmed it is conjectured that this issue may only be exploitable when debugging functionality is enabled.
Exploit / POC
ISC DHCPD Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ISC DHCPD Remote Format String Vulnerability
Solution:
It is reported that the vendor has released an update to address this vulnerability. This update is reported to be located at:
ftp://ftp.isc.org/isc/dhcp/dhcp-3.0.2rc1.tar.gz
This is not confirmed by Symantec, users are advised to contact the vendor for further information.
Debian has released an advisory (DSA 584-1) and fixes to address this issue. Please see the referenced advisory for further information regarding obtaining and applying appropriate updates.
RedHat Linux has released advisory RHSA-2005:212-06 to address this issue in RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
RedHat Fedora has released Fedora Legacy security advisory FLSA:152835 addressing this issue. Please see the referenced advisory for further information.
ISC DHCPD 2.0.pl5
Solution:
It is reported that the vendor has released an update to address this vulnerability. This update is reported to be located at:
ftp://ftp.isc.org/isc/dhcp/dhcp-3.0.2rc1.tar.gz
This is not confirmed by Symantec, users are advised to contact the vendor for further information.
Debian has released an advisory (DSA 584-1) and fixes to address this issue. Please see the referenced advisory for further information regarding obtaining and applying appropriate updates.
RedHat Linux has released advisory RHSA-2005:212-06 to address this issue in RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
RedHat Fedora has released Fedora Legacy security advisory FLSA:152835 addressing this issue. Please see the referenced advisory for further information.
ISC DHCPD 2.0.pl5
-
Debian dhcp-client_2.0pl5-11woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_alpha.deb -
Debian dhcp-client_2.0pl5-11woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_arm.deb -
Debian dhcp-client_2.0pl5-11woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_hppa.deb -
Debian dhcp-client_2.0pl5-11woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_i386.deb -
Debian dhcp-client_2.0pl5-11woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_ia64.deb -
Debian dhcp-client_2.0pl5-11woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_m68k.deb -
Debian dhcp-client_2.0pl5-11woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_mips.deb -
Debian dhcp-client_2.0pl5-11woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_mipsel.deb -
Debian dhcp-client_2.0pl5-11woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_powerpc.deb -
Debian dhcp-client_2.0pl5-11woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_s390.deb -
Debian dhcp-client_2.0pl5-11woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-client_2.0pl5 -11woody1_sparc.deb -
Debian dhcp-relay_2.0pl5-11woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_alpha.deb -
Debian dhcp-relay_2.0pl5-11woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_arm.deb -
Debian dhcp-relay_2.0pl5-11woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_hppa.deb -
Debian dhcp-relay_2.0pl5-11woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_i386.deb -
Debian dhcp-relay_2.0pl5-11woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_ia64.deb -
Debian dhcp-relay_2.0pl5-11woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_m68k.deb -
Debian dhcp-relay_2.0pl5-11woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_mips.deb -
Debian dhcp-relay_2.0pl5-11woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_mipsel.deb -
Debian dhcp-relay_2.0pl5-11woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_powerpc.deb -
Debian dhcp-relay_2.0pl5-11woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_s390.deb -
Debian dhcp-relay_2.0pl5-11woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp-relay_2.0pl5- 11woody1_sparc.deb -
Debian dhcp_2.0pl5-11woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_alpha.deb -
Debian dhcp_2.0pl5-11woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_arm.deb -
Debian dhcp_2.0pl5-11woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_hppa.deb -
Debian dhcp_2.0pl5-11woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_i386.deb -
Debian dhcp_2.0pl5-11woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_ia64.deb -
Debian dhcp_2.0pl5-11woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_m68k.deb -
Debian dhcp_2.0pl5-11woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_mips.deb -
Debian dhcp_2.0pl5-11woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_mipsel.deb -
Debian dhcp_2.0pl5-11woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_powerpc.deb -
Debian dhcp_2.0pl5-11woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_s390.deb -
Debian dhcp_2.0pl5-11woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/d/dhcp/dhcp_2.0pl5-11wood y1_sparc.deb -
RedHat dhcp-2.0pl5-8.2.legacy.i386.rpm
RedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/dhcp-2.0pl5-8 .2.legacy.i386.rpm
References
ISC DHCPD Remote Format String Vulnerability
References:
References:
- RHSA-2005:212-06 - dhcp security update (RedHat)
- Re: debian dhcpd, old format string bug (Javier Fernandez-Sanguino
)