GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Sep 03, 2014 4:26 pm Post subject: [ GLSA 201409-03 ] dhcpcd: Denial of service |
|
|
Gentoo Linux Security Advisory
Title: dhcpcd: Denial of service (GLSA 201409-03)
Severity: normal
Exploitable: remote
Date: September 03, 2014
Bug(s): #518596
ID: 201409-03
Synopsis
A vulnerability in dhcpcd can lead to a Denial of Service
condition.
Background
dhcpcd is a fully featured, yet light weight RFC2131 compliant DHCP
client.
Affected Packages
Package: net-misc/dhcpcd
Vulnerable: < 6.4.3
Unaffected: >= 6.4.3
Architectures: All supported architectures
Description
A vulnerability has been discovered in dhcpcd. A malicious dhcp server
can set flags as part of the dhcp reply that can cause a Denial of
Service condition.
Impact
A remote attacker can cause a Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All dhcpcd users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/dhcpcd-6.4.3"
|
References
CVE-2014-6060 |
|