Oval Definition:oval:com.redhat.rhsa:def:20121141
Revision Date:2012-08-03Version:635
Title:RHSA-2012:1141: dhcp security update (Moderate)
Description:The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows individual devices on an IP network to get their own network configuration information, including an IP address, a subnet mask, and a broadcast address.

  • A denial of service flaw was found in the way the dhcpd daemon handled zero-length client identifiers. A remote attacker could use this flaw to send a specially-crafted request to dhcpd, possibly causing it to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2012-3571)

  • Two memory leak flaws were found in the dhcpd daemon. A remote attacker could use these flaws to cause dhcpd to exhaust all available memory by sending a large number of DHCP requests. (CVE-2012-3954)

    Upstream acknowledges Markus Hietava of the Codenomicon CROSS project as the original reporter of CVE-2012-3571, and Glen Eustace of Massey University, New Zealand, as the original reporter of CVE-2012-3954.

    Users of DHCP should upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, all DHCP servers will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-3571
    CVE-2012-3571
    CVE-2012-3954
    CVE-2012-3954
    RHSA-2012:1141
    RHSA-2012:1141-01
    RHSA-2012:1141-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • dhclient is earlier than 12:4.1.1-31.P1.el6_3.1
  • AND dhclient is signed with Red Hat redhatrelease2 key
  • dhcp is earlier than 12:4.1.1-31.P1.el6_3.1
  • AND dhcp is signed with Red Hat redhatrelease2 key
  • dhcp-common is earlier than 12:4.1.1-31.P1.el6_3.1
  • AND dhcp-common is signed with Red Hat redhatrelease2 key
  • dhcp-devel is earlier than 12:4.1.1-31.P1.el6_3.1
  • AND dhcp-devel is signed with Red Hat redhatrelease2 key
  • BACK