DHCPCD Remote Denial of Service Vulnerability
BID:14206
Info
DHCPCD Remote Denial of Service Vulnerability
| Bugtraq ID: | 14206 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-1848 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to infamous42md. |
| Vulnerable: |
Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux -current Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Phystech dhcpcd 1.3.22 -pl4 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 IPCop IPCop 1.4.6 IPCop IPCop 1.4.5 IPCop IPCop 1.4.4 IPCop IPCop 1.4.2 IPCop IPCop 1.4.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
DHCPCD Remote Denial of Service Vulnerability
dhcpcd is prone to a remote denial of service vulnerability.
The issue presents itself when the application handles malformed data and accesses out of bounds memory.
dhcpcd 1.3.22pl4 is reported to be affected. It is possible that older versions are vulnerable as well.
dhcpcd is prone to a remote denial of service vulnerability.
The issue presents itself when the application handles malformed data and accesses out of bounds memory.
dhcpcd 1.3.22pl4 is reported to be affected. It is possible that older versions are vulnerable as well.
Exploit / POC
DHCPCD Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
DHCPCD Remote Denial of Service Vulnerability
Solution:
Debian has released advisory DSA 750-1 to address this issue. Please see the referenced advisory for more information.
Mandriva has released advisory MDKSA-2005:117, along with fixes to address this issue. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200507-16 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/dhcpcd-1.3.22_p4-r11"
Conectiva Linux has released security advisory CLSA-2005:983 addressing this issue for Conectiva Linux 9 and 10. Please see the referenced advisory for further information.
RedHat Linux has released security advisory RHSA-2005:603-07 addressing this issue for their Enterprise and Advanced Workstation editions. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
An updated version of IPCop is available to address this and other issues.
Slackware Linux has released advisory SSA:2005-255-01, along with fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Phystech dhcpcd 1.3.22 -pl4
IPCop IPCop 1.4.1
IPCop IPCop 1.4.2
IPCop IPCop 1.4.4
IPCop IPCop 1.4.5
IPCop IPCop 1.4.6
Slackware Linux 10.0
Slackware Linux 10.1
Slackware Linux 8.1
Slackware Linux 9.0
Slackware Linux 9.1
Solution:
Debian has released advisory DSA 750-1 to address this issue. Please see the referenced advisory for more information.
Mandriva has released advisory MDKSA-2005:117, along with fixes to address this issue. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200507-16 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/dhcpcd-1.3.22_p4-r11"
Conectiva Linux has released security advisory CLSA-2005:983 addressing this issue for Conectiva Linux 9 and 10. Please see the referenced advisory for further information.
RedHat Linux has released security advisory RHSA-2005:603-07 addressing this issue for their Enterprise and Advanced Workstation editions. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
An updated version of IPCop is available to address this and other issues.
Slackware Linux has released advisory SSA:2005-255-01, along with fixes to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Phystech dhcpcd 1.3.22 -pl4
-
Debian dhcpcd_1.3.22pl4-21sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_alpha.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_amd64.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_arm.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_hppa.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_i386.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_ia64.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_m68k.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_mips.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_mipsel.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_powerpc.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_s390.deb -
Debian dhcpcd_1.3.22pl4-21sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.22pl4 -21sarge1_sparc.deb
IPCop IPCop 1.4.1
-
IPCop IPCop 1.4.8
http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848
IPCop IPCop 1.4.2
-
IPCop IPCop 1.4.8
http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848
IPCop IPCop 1.4.4
-
IPCop IPCop 1.4.8
http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848
IPCop IPCop 1.4.5
-
IPCop IPCop 1.4.8
http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848
IPCop IPCop 1.4.6
-
IPCop IPCop 1.4.8
http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848
Slackware Linux 10.0
-
Slackware dhcpcd-1.3.22pl4-i486-2.tgz
Slackware 10.0
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ dhcpcd-1.3.22pl4-i486-2.tgz
Slackware Linux 10.1
-
Slackware dhcpcd-1.3.22pl4-i486-2.tgz
Slackware 10.0
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ dhcpcd-1.3.22pl4-i486-2.tgz
Slackware Linux 8.1
-
Slackware dhcpcd-1.3.22pl4-i386-2.tgz
Slackware 8.1
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/d hcpcd-1.3.22pl4-i386-2.tgz
Slackware Linux 9.0
-
Slackware dhcpcd-1.3.22pl4-i386-2.tgz
Slackware 9.0
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/d hcpcd-1.3.22pl4-i386-2.tgz
Slackware Linux 9.1
-
Slackware dhcpcd-1.3.22pl4-i486-2.tgz
Slackware 9.1
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/d hcpcd-1.3.22pl4-i486-2.tgz
References
DHCPCD Remote Denial of Service Vulnerability
References:
References:
- DHCPCD Product Page (Phystec)
- IPCop 1.4.8 Release Notes (IPCop)
- RHSA-2005:603-07 - Moderate: dhcpcd security update (RedHat)