Oval Definition:oval:org.mitre.oval:def:12418
Revision Date:2014-07-07Version:20
Title:USN-803-2 -- dhcp3 vulnerability
Description:USN-803-1 fixed a vulnerability in Dhcp. Due to an error, the patch to fix the vulnerability was not properly applied on Ubuntu 8.10 and higher. Even with the patch improperly applied, the default compiler options reduced the vulnerability to a denial of service. Additionally, in Ubuntu 9.04 and higher, users were also protected by the AppArmor dhclient3 profile. This update fixes the problem. Original advisory details: It was discovered that the DHCP client as included in dhcp3 did not verify the length of certain option fields when processing a response from an IPv4 dhcp server. If a user running Ubuntu 6.06 LTS or 8.04 LTS connected to a malicious dhcp server, a remote attacker could cause a denial of service or execute arbitrary code as the user invoking the program, typically the "dhcp" user. For users running Ubuntu 8.10 or 9.04, a remote attacker should only be able to cause a denial of service in the DHCP client. In Ubuntu 9.04, attackers would also be isolated by the AppArmor dhclient3 profile.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-0692
USN-803-2
USN-803-2
Platform(s):Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10
Product(s):dhcp3
Definition Synopsis
  • Release section
  • Ubuntu 8.10 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • dhcp3-client DPKG is earlier than 3.1.1-1ubuntu2.2
  • OR dhcp3-dev DPKG is earlier than 3.1.1-1ubuntu2.2
  • OR dhcp3-relay DPKG is earlier than 3.1.1-1ubuntu2.2
  • OR dhcp3-common DPKG is earlier than 3.1.1-1ubuntu2.2
  • OR dhcp3-server-ldap DPKG is earlier than 3.1.1-1ubuntu2.2
  • OR dhcp3-server DPKG is earlier than 3.1.1-1ubuntu2.2
  • OR dhcp3-client-udeb DPKG is earlier than 3.1.1-1ubuntu2.2
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND dhcp-client DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • dhcp3-client DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR dhcp3-dev DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR dhcp3-relay DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR dhcp3-common DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR dhcp3-server-ldap DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR dhcp3-server DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR dhcp3-client-udeb DPKG is earlier than 3.1.2-1ubuntu7.1
  • OR Release section
  • Ubuntu 9.04 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND dhcp-client DPKG is earlier than 3.1.1-5ubuntu8.2
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • dhcp3-client DPKG is earlier than 3.1.1-5ubuntu8.2
  • OR dhcp3-dev DPKG is earlier than 3.1.1-5ubuntu8.2
  • OR dhcp3-relay DPKG is earlier than 3.1.1-5ubuntu8.2
  • OR dhcp3-common DPKG is earlier than 3.1.1-5ubuntu8.2
  • OR dhcp3-server-ldap DPKG is earlier than 3.1.1-5ubuntu8.2
  • OR dhcp3-server DPKG is earlier than 3.1.1-5ubuntu8.2
  • OR dhcp3-client-udeb DPKG is earlier than 3.1.1-5ubuntu8.2
  • BACK