New User, Welcome!     Login

Next Page >>

dhcp

=?UTF-8?B?Q09SRS0yMDA3LTA5Mjg6IFN0YWNrLWJhc2VkIGJ1ZmZlciBvdmVyZmw=?= =?UTF-8?B?b3cgdnVsbmVyYWJpbGl0eSBpbiBPcGVuQlNE4oCZcyBESENQIHNlcnZlcg==?=

Hash: SHA1

        Core Security Technologies – CoreLabs Advisory
             http://www.coresecurity.com/corelabs

Stack-based buffer overflow vulnerability in OpenBSD’s DHCP server

*Advisory Information*

Title: Stack-based buffer overflow vulnerability in OpenBSD’s DHCP server


VMSA-2009-0014 VMware ESX patches for DHCP, Service Console kernel, and JRE resolve multiple security issues

- -----------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2009-0014
Synopsis:          VMware ESX patches for DHCP, Service Console kernel,
                   and JRE resolve multiple security issues
Issue date:        2009-10-16
Updated on:        2009-10-16 (initial release of advisory)
CVE numbers:       CVE-2009-0692 CVE-2009-1893 CVE-2009-0692
                   CVE-2008-4210 CVE-2008-3275 CVE-2008-5356

[ MDVSA-2009:312 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2009:312
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : December 3, 2009
 Affected: 2008.0
 _______________________________________________________________________

 Problem Description:

[ GLSA 200808-05 ] ISC DHCP: Denial of Service

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: ISC DHCP: Denial of Service
      Date: August 06, 2008
      Bugs: #227135
        ID: 200808-05

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[USN-531-2] dhcp vulnerability

=========================================================== 
Ubuntu Security Notice USN-531-2           October 23, 2007
dhcp vulnerability
CVE-2007-5365
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 6.10

[USN-531-1] dhcp vulnerability

=========================================================== 
Ubuntu Security Notice USN-531-1           October 22, 2007
dhcp vulnerability
CVE-2007-5365
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 6.10

[USN-803-2] Dhcp vulnerability

===========================================================
Ubuntu Security Notice USN-803-2           January 27, 2010
dhcp3 vulnerability
CVE-2009-0692
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.10
Ubuntu 9.04

[ GLSA 200907-12 ] ISC DHCP: dhcpclient Remote execution of arbitrary code

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: High
     Title: ISC DHCP: dhcpclient Remote execution of arbitrary code
      Date: July 14, 2009
      Bugs: #277729
        ID: 200907-12

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[USN-803-1] dhcp vulnerability

===========================================================
Ubuntu Security Notice USN-803-1              July 14, 2009
dhcp3 vulnerability
CVE-2009-0692
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS

[SECURITY] [DSA 1388-1] New dhcp packages fix arbitrary code execution

Debian Security Advisory DSA 1388-1                  security@debian.org
http://www.debian.org/security/                               Steve Kemp
October 18th, 2007                    http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : dhcp
Vulnerability  : buffer overflow
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2007-5365
Debian Bug     : 446354

[ GLSA 200908-08 ] ISC DHCP: dhcpd Denial of Service

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: ISC DHCP: dhcpd Denial of Service
      Date: August 18, 2009
      Bugs: #275231
        ID: 200908-08

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[ MDVSA-2009:153 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2009:153
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : July 17, 2009
 Affected: 2008.1, Corporate 3.0, Corporate 4.0,
           Multi Network Firewall 2.0
 _______________________________________________________________________


[ MDVSA-2009:154 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2009:154
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : July 19, 2009
 Affected: 2008.1, 2009.0, 2009.1, Corporate 3.0, Corporate 4.0,
           Multi Network Firewall 2.0
 _______________________________________________________________________


[ MDVSA-2009:172 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2009:172
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : July 28, 2009
 Affected: Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

[ MDVSA-2011:073 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2011:073
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : April 11, 2011
 Affected: 2009.0, 2010.0, 2010.1, Corporate 4.0, Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

[ MDVSA-2011:128 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2011:128
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : August 18, 2011
 Affected: 2009.0, 2010.1, Corporate 4.0, Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

Exposing HMS HICP Protocol + Intellicom NetBiterConfig.exe Remote Buffer Overflow (Not patched)

+”module version = 0.66.6; ” # ...
+”mac = 00-30-11-00-CA-FE; ” # MAC
+”ip = 192.168.1.252; ” # ...
+”sn = 255.255.255.0; ” # Network Mask
+”gw = 192.168.1.1; ” # Gateway
+”dhcp = off; ” # whether the device is using a DHCP server for
obtaining the IP address. (on/off)
+”pswd = off; ” # whether the device is using a PASSWORD(on/off)
+”hn = morroBufalo; ” # hostname (optional)
+”dns1 = 192.168.1.33; ” # Primary DNS
+”dns2 = 192.168.1.34; ” # Secondary DNS (optional)

[ MDVSA-2009:151 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2009:151
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : July 15, 2009
 Affected: 2008.1, 2009.0, 2009.1, Corporate 3.0, Corporate 4.0,
           Multi Network Firewall 2.0
 _______________________________________________________________________


[USN-1108-2] DHCP vulnerability

==========================================================================
Ubuntu Security Notice USN-1108-2
April 19, 2011

dhcp3 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.10

[ MDVSA-2010:226 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2010:226
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : November 10, 2010
 Affected: 2009.1, 2010.0, 2010.1
 _______________________________________________________________________

 Problem Description:

[ MDVSA-2010:114 ] dhcp

 Mandriva Linux Security Advisory                         MDVSA-2010:114
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : dhcp
 Date    : June 11, 2010
 Affected: 2009.1, 2010.0
 _______________________________________________________________________

 Problem Description:

[SECURITY] [DSA 2216-1] isc-dhcp security update

Debian Security Advisory DSA-2216-1                   security@debian.org
http://www.debian.org/security/                                Nico Golde
April 10, 2011                         http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : isc-dhcp
Vulnerability  : missing input sanitization
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2011-0997
Debian bug     : 621099

[SECURITY] [DSA 1833-2] New dhcp3 packages fix arbitrary code execution

Debian Security Advisory DSA-1833-2                  security@debian.org
http://www.debian.org/security/                           Florian Weimer
August 25, 2009                       http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : dhcp3
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2009-0692 CVE-2009-1892
CERT advisory  : VU#410676

[ GLSA 200809-02 ] dnsmasq: Denial of Service and DNS spoofing

spoofing of DNS replies.

Background
==========

Dnsmasq is a lightweight and easily-configurable DNS forwarder and DHCP
server.

Affected packages
=================


[SECURITY] [DSA 1388-3] New dhcp packages fix arbitrary code execution

Debian Security Advisory DSA-1388-3                security@debian.org
http://www.debian.org/security/                         Noah Meyerhans
October 29, 2007                    http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : dhcp
Vulnerability  : buffer overflow
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2007-5365
Debian Bug     : 446354

[USN-1037-1] ifupdown update

  ifupdown                        0.6.8ubuntu29.2

Ubuntu 10.10:
  ifupdown                        0.6.10ubuntu3.1

After a standard system update you need to restart your DHCP network
interfaces to make all the necessary changes.

Details follow:

Under certain circumstances, the DHCP client could start before its

[SECURITY] [DSA 2217-1] dhcp3 security update

Debian Security Advisory DSA-2217-1                   security@debian.org
http://www.debian.org/security/                                Nico Golde
April 10, 2011                         http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : dhcp3
Vulnerability  : missing input sanitization
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2011-0997


[SECURITY] [DSA 1833-1] New dhcp3 packages fix arbitrary code execution

Debian Security Advisory DSA-1833-1                  security@debian.org
http://www.debian.org/security/                           Florian Weimer
July 14, 2009                         http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : dhcp3
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2009-0692 CVE-2009-1892
CERT advisory  : VU#410676

VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player

     VMware Player      1.0.4 upgrade to version 1.0.5 (Build# 56455)
     VMware Server      1.0.3 upgrade to version 1.0.4 (Build# 56528)
     VMware ACE         2.0.0 upgrade to version 2.0.1 (Build# 55017)
     VMware ACE         1.0.3 upgrade to version 1.0.4 (Build# 54075)

II   Hosted products DHCP security vulnerabilities addressed

     This release fixes several vulnerabilities in the DHCP server
     that could enable a specially crafted packets to gain system-level
     privileges. (CVE-2007-0061, CVE-2007-0062, CVE-2007-0063)


VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues

~     VMware ACE         1.0 upgrade to version 1.0.5 (Build# 79846)

~     NOTE: Fusion and Linux based products are not affected by this
~           issue.

~ g.  DHCP denial of service vulnerability

~     A potential denial of service issue affects DHCP service running
~     on the host.

~     VMware would like to thank Martin O'Neal for reporting this issue.

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!