Bug 40546 - isc-dhcp: Denial of service (4.0)
isc-dhcp: Denial of service (4.0)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.0
Other Linux
: P5 normal (vote)
: UCS 4.0-4-errata
Assigned To: Philipp Hahn
Janek Walkenhorst
:
Depends on: 40545
Blocks: 40547
  Show dependency treegraph
 
Reported: 2016-02-01 11:45 CET by Arvid Requate
Modified: 2016-04-06 14:04 CEST (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2016-02-01 11:45:19 CET
+++ This bug was initially created as a clone of Bug #40545 +++

Upstream Debian package version 4.2.2.dfsg.1-5+deb70u8 fixes this issue:

* ISC dhcp allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet (CVE-2015-8605)
Comment 1 Philipp Hahn univentionstaff 2016-02-23 12:34:25 CET
repo_admin.py -U -p isc-dhcp -d wheezy -r 4.0-0-0 -s errata4.0-4

r15950 | Bug #40546 dhcp: Fix patch application
r15951 | Bug #40546 dhcp: Refresh patch application
r15982 | Bug #40546 dhcp: FTBFS .NOTPARALLEL:

Package: isc-dhcp
Version: 4.2.2.dfsg.1-5+deb70u8.36.201602231227
Branch: ucs_4.0-0
Scope: errata4.0-4

r67629 | Bug #40546 dhcp: YAML 4.0-4
 isc-dhcp.yaml
Comment 2 Arvid Requate univentionstaff 2016-03-29 13:07:56 CEST
Another issue, maybe we can pick up the patch too if it is available in short term:

* ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions. (CVE-2016-2774)
Comment 3 Janek Walkenhorst univentionstaff 2016-03-31 18:12:27 CEST
(In reply to Arvid Requate from comment #2)
> Another issue, maybe we can pick up the patch too if it is available in
> short term:
> 
> * ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does
> not restrict the number of concurrent TCP sessions, which allows remote
> attackers to cause a denial of service (INSIST assertion failure or
> request-processing outage) by establishing many sessions. (CVE-2016-2774)
This is a minor issue, ignored.
Comment 4 Janek Walkenhorst univentionstaff 2016-03-31 19:35:53 CEST
Tests (amd64): OK
Advisory: OK
Comment 5 Philipp Hahn univentionstaff 2016-04-06 14:04:03 CEST
<http://errata.software-univention.de/ucs/4.0/409.html>