Rapid7 Vulnerability & Exploit Database

SUSE-SA:2003:0006: dhcp

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

SUSE-SA:2003:0006: dhcp

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
01/20/2003
Created
07/25/2018
Added
11/08/2005
Modified
11/18/2015

Description

The ISC (Internet Software Consortium) dhcp package is an implementation of the "Dynamic Host Configuration Protocol" (DHCP). An internal source code audit done by ISC revealed several buffer overflows in the code which is responsible to handle dynamic DNS requests. These bugs allow an attacker to gain remote access to the dhcp server if the dynamic DNS feature is enabled. Dynamic DNS is not enabled by default on SUSE Linux.

As temporary fix you can disable dynamic DNS support and restart your dhcp server. Otherwise install the new packages from our FTP servers.

Please backup your lease file before updating the package. After the package update you have to restart the dhcp server This can be done by executing the following commands as root:

  • rcdhcpd restart or (for older versions):
  • rcdhcp restart

Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. Our maintenance customers are being notified individually. The packages are being offered to install from the maintenance web.

Solution(s)

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;