[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2011-0256 -- Oracle dhcp

ID: oval:org.secpod.oval:def:1503447Date: (C)2021-01-08   (M)2021-09-11
Class: PATCHFamily: unix




Updated dhcp packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available from the CVE link in the References section. Description The Dynamic Host Configuration Protocol is a protocol that allows individual devices on an IP network to get their own network configuration information, including an IP address, a subnet mask, and a broadcast address. DHCPv6 is the DHCP protocol version for IPv6 networks. A flaw was found in the way the dhcpd daemon processed certain DHCPv6 messages for addresses that had previously been declined and marked as abandoned internally. If a remote attacker sent such messages to dhcpd, it could cause dhcpd to crash due to an assertion failure if it was running as a DHCPv6 server. Red Hat would like to thank Internet Systems Consortium for reporting this issue. Users running dhcpd as a DHCPv6 server should upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, all DHCP servers will be restarted automatically.

Platform:
Oracle Linux 6
Product:
dhcp
Reference:
ELSA-2011-0256
CVE-2011-0413
CVE    1
CVE-2011-0413
CPE    14
cpe:/a:isc:dhcp:4.1.1:rc1
cpe:/a:isc:dhcp:4.2.0:a2
cpe:/a:isc:dhcp:4.2.0:a1
cpe:/a:isc:dhcp:4.0.3:rc1
...

© SecPod Technologies