Univention Bugzilla – Bug 53394
isc-dhcp: Multiple issues (4.4)
Last modified: 2021-06-09 18:27:38 CEST
New Debian isc-dhcp 4.3.5-3+deb9u2A~4.4.8.202106041236 fixes: This update addresses the following issue: * stack-based buffer overflow when parsing statements with colon-separated hex digits in config or lease files in dhcpd and dhclient (CVE-2021-25217)
--- mirror/ftp/4.4/unmaintained/4.4-1/source/isc-dhcp_4.3.5-3+deb9u1A~4.4.0.201903251533.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/isc-dhcp_4.3.5-3+deb9u2A~4.4.8.202106041236.dsc @@ -1,4 +1,4 @@ -4.3.5-3+deb9u1A~4.4.0.201903251533 [Mon, 25 Mar 2019 15:33:11 +0100] Univention builddaemon <buildd@univention.de>: +4.3.5-3+deb9u2A~4.4.8.202106041236 [Fri, 04 Jun 2021 12:40:53 +0200] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 10_fix_28139_ranges @@ -12,6 +12,12 @@ 30_policy 30_policy +4.3.5-3+deb9u2 [Thu, 03 Jun 2021 11:56:24 +0200] Emilio Pozuelo Monfort <pochu@debian.org>: + + * Non-maintainer upload by the LTS Team. + * CVE-2021-25217: denial of service in server and client via application + crash when parsing lease information. + 4.3.5-3+deb9u1 [Sat, 03 Mar 2018 17:27:05 +0100] Salvatore Bonaccorso <carnil@debian.org>: * Non-maintainer upload by the Security Team. <http://piuparts.knut.univention.de/4.4-8/#7301144747776868736>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 53839cc668 Bug #53394: isc-dhcp 4.3.5-3+deb9u2A~4.4.8.202106041236 doc/errata/staging/isc-dhcp.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [4.4-8] a1382b8c6b Bug #53394: isc-dhcp 4.3.5-3+deb9u2A~4.4.8.202106041236 doc/errata/staging/isc-dhcp.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x990>