You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa isc-dhcp

Sigurnosni nedostatak programskog paketa isc-dhcp

==========================================================================
Ubuntu Security Notice USN-3973-1
May 13, 2019

isc-dhcp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.10
– Ubuntu 18.04 LTS

Summary:

DHCP could be made to crash if it received specially crafted network
traffic.

Software Description:
– isc-dhcp: DHCP server and client

Details:

It was discovered that DHCP, when built with a mismatched external BIND
library, incorrectly handled certain memory operations. A remote attacker
could possibly use this issue to cause DHCP to crash, resulting in a
denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
isc-dhcp-server 4.3.5-3ubuntu9.1

Ubuntu 18.04 LTS:
isc-dhcp-server 4.3.5-3ubuntu7.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3973-1
CVE-2019-6470

Package Information:
https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.5-3ubuntu9.1
https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.5-3ubuntu7.1

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlzZilkACgkQZWnYVadE
vpNf6BAAqV2konDWth1dxxVaw0rlf0qjxVXzkGLUlJrwWntLDQZlaTyt6K7T//EO
zBhp9xzYhSDOwApXwHNHGfcdPEc0EcoEwa//DYpt17FJO4issuFoQtumbIIw5m9S
IcZcTcw/xYUJPDomygpADCaUXeSf2EFj/bPhHW0E5HZhbLhfS3EEUFjPbyAbl6QN
zPQwi05GxMYt7Wv0/pjxw9h+QU72HgvmxYkwdKeC1w7b/mlYYatw2TjNlN9z/Gjw
U0C/wIsJjqNhnJyfIKfEhH1wdBEyJR8F9WtHmJ8AHpJFUSKA2MsmzXoLiY4aitfx
64jYTW2hxt4Dz5ZzMpSdT+SHnPcktBtONRtSwjxhKfPAcGHIIDddiT22eNj7Mmgu
/vz42CQ/sPehiI14R0Fqn6fieMBn2gHqGCUz0QN1Ygl+zjyHP5Z9FPXor0zcpWtR
W2mRU2X0lhzcwvopH+Q1Zko9hRufiOrbLtop0eQG8C/TvYozCwZj7dNEsBgutFNk
nIbjiLv44jXHcEEaSLhMsyto93A/FJOz01s2SnP2qTTXK9OL1rNSW5aa51OppTS1
XqdG4FtVWLPA5LTmsT6/lp15Z6gYkvFoemALz1z3UymhWw7Xsxj/F/ODj00dQ8Ek
PLyh6gEwD4bss+E4EVDk0nSXyxbsZRS3qfDQshMhX+J2ZrNLcE8=
=SmX2
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa ghostscript

Otkriven je sigurnosni nedostatak u programskom paketu ghostscript za operacijski sustav Debian. Otkriveni nedostatak potencijalnim napadačima omogućuje izazivanje DoS stanja,...

Close