星球 - USN-1108-1: DHCP vulnerability

來自:Ubuntu security notices | 2011/4/15 4:12:51

Ubuntu Security Notice USN-1108-1


11th April, 2011


dhcp3 vulnerability


A security issue affects these releases of Ubuntu and its
derivatives:




  • Ubuntu 10.10


  • Ubuntu 10.04 LTS


  • Ubuntu 9.10


  • Ubuntu 8.04 LTS


  • Ubuntu 6.06 LTS





Summary


An attacker's DHCP server could send crafted responses to your computer
and cause it to run programs as root.





Software description





  • dhcp3
    - DHCP Client















Details


Sebastian Krahmer discovered that the dhclient utility incorrectly filtered
crafted responses. An attacker could use this flaw with a malicious DHCP
server to execute arbitrary code, resulting in root privilege escalation.



Update instructions


The problem can be corrected by updating your system to the following
package version:




Ubuntu 10.10:




dhcp3-client

3.1.3-2ubuntu6.1





Ubuntu 10.04 LTS:




dhcp3-client

3.1.3-2ubuntu3.1





Ubuntu 9.10:




dhcp3-client

3.1.2-1ubuntu7.2





Ubuntu 8.04 LTS:




dhcp3-client

3.0.6.dfsg-1ubuntu9.2





Ubuntu 6.06 LTS:




dhcp3-client

3.0.3-6ubuntu7.2








In general, a standard system update will make all the necessary changes.





References




CVE-2011-0997