Oval Definition:oval:com.redhat.rhsa:def:20091154
Revision Date:2009-07-14Version:635
Title:RHSA-2009:1154: dhcp security update (Critical)
Description:The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows individual devices on an IP network to get their own network configuration information, including an IP address, a subnet mask, and a broadcast address.

  • The Mandriva Linux Engineering Team discovered a stack-based buffer overflow flaw in the ISC DHCP client. If the DHCP client were to receive a malicious DHCP response, it could crash or execute arbitrary code with the permissions of the client (root). (CVE-2009-0692)

  • An insecure temporary file use flaw was discovered in the DHCP daemon's init script ("/etc/init.d/dhcpd"). A local attacker could use this flaw to overwrite an arbitrary file with the output of the "dhcpd -t" command via a symbolic link attack, if a system administrator executed the DHCP init script with the "configtest", "restart", or "reload" option. (CVE-2009-1893)

    Users of DHCP should upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0692
    CVE-2009-1893
    RHSA-2009:1154
    RHSA-2009:1154-02
    RHSA-2009:1154-02
    Platform(s):Red Hat Enterprise Linux 3
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • dhclient is earlier than 7:3.0.1-10.2_EL3
  • AND dhclient is signed with Red Hat master key
  • dhcp is earlier than 7:3.0.1-10.2_EL3
  • AND dhcp is signed with Red Hat master key
  • dhcp-devel is earlier than 7:3.0.1-10.2_EL3
  • AND dhcp-devel is signed with Red Hat master key
  • BACK