Bug 40545

Summary: isc-dhcp: Denial of service (4.1)
Product: UCS Reporter: Arvid Requate <requate>
Component: Security updatesAssignee: Philipp Hahn <hahn>
Status: CLOSED FIXED QA Contact: Janek Walkenhorst <walkenhorst>
Severity: normal    
Priority: P5 CC: gohmann, hahn
Version: UCS 4.1Flags: requate: Patch_Available+
Target Milestone: UCS 4.1-1-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: Security Issue What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): Security
Max CVSS v3 score:
Bug Depends on:    
Bug Blocks: 40546, 40547    

Description Arvid Requate univentionstaff 2016-02-01 11:44:41 CET
Upstream Debian package version 4.2.2.dfsg.1-5+deb70u8 fixes this issue:

* ISC dhcp allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet (CVE-2015-8605)
Comment 1 Philipp Hahn univentionstaff 2016-02-23 12:42:17 CET
repo_admin.py --cherrypick -r 4.0 -s errata4.0-4 --releasedest 4.1 --dest errata4.1-1 -p isc-dhcp

Package: isc-dhcp
Version: 4.2.2.dfsg.1-5+deb70u8.37.201602231237
Branch: ucs_4.1-0
Scope: errata4.1-1

r67630 | Bug #40545 dhcp: YAML 4.1-1
 isc-dhcp.yaml
Comment 2 Arvid Requate univentionstaff 2016-03-29 13:07:03 CEST
Another issue, maybe we can pick up the patch too if it is available in short term:

* ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions. (CVE-2016-2774)
Comment 3 Janek Walkenhorst univentionstaff 2016-03-31 18:12:26 CEST
(In reply to Arvid Requate from comment #2)
> Another issue, maybe we can pick up the patch too if it is available in
> short term:
> 
> * ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does
> not restrict the number of concurrent TCP sessions, which allows remote
> attackers to cause a denial of service (INSIST assertion failure or
> request-processing outage) by establishing many sessions. (CVE-2016-2774)
This is a minor issue, ignored.
Comment 4 Janek Walkenhorst univentionstaff 2016-03-31 19:35:54 CEST
Tests (amd64): OK
Advisory: OK
Comment 5 Janek Walkenhorst univentionstaff 2016-04-06 13:14:53 CEST
<http://errata.software-univention.de/ucs/4.1/138.html>