===================================================================== CERT-Renater Note d'Information No. 2011/VULN189 _____________________________________________________________________ DATE : 07/03/2011 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Debian version wheezy, sid, squeeze running isc-dhcp version prior to 4.1.1-P1-16, 4.1.1-P1-15+squeeze1. ====================================================================== http://www.debian.org/security/2011/dsa-2184 ______________________________________________________________________ - ------------------------------------------------------------------------- Debian Security Advisory DSA-2184-1 security at debian.org http://www.debian.org/security/ Florian Weimer March 05, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : isc-dhcp Vulnerability : denial of service Problem type : remote Debian-specific: no CVE ID : CVE-2011-0413 Debian Bug : 611217 It was discovered that the ISC DHCPv6 server does not correctly process requests which come from unexpected source addresses, leading to an assertion failure and a daemon crash. The oldstable distribution (lenny) is not affected by this problem. For the stable distribution (squeeze), this problem has been fixed in version 4.1.1-P1-15+squeeze1. For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 4.1.1-P1-16. We recommend that you upgrade your isc-dhcp packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce at lists.debian.org ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================