Dit bericht is nog niet vertaald

[USN-531-2] dhcp vulnerability

Ubuntu Security Notice USN-531-2           October 23, 2007
dhcp vulnerability
CVE-2007-5365
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
dhcp 2.0pl5-19.4ubuntu0.2
Ubuntu 6.10
dhcp 2.0pl5-19.4ubuntu1.2
Ubuntu 7.10
dhcp 2.0pl5dfsg1-20ubuntu1.2
Ubuntu 7.04
dhcp 2.0pl5-19.5ubuntu2.2

In general, a standard system upgrade is sufficient to affect the necessary changes.

USN-531-1 fixed vulnerabilities in dhcp. The fixes were incomplete, and only reduced the scope of the vulnerability, without fully solving it. This update fixes the problem. Original advisory details: Nahuel Riva and Gerardo Richarte discovered that the DHCP server did not correctly handle certain client options. A remote attacker could send malicious DHCP replies to the server and execute arbitrary code.