MGASA-2016-0028
Dashboard / Vulnerabilities / MGASA-2016-0028
Summary: Updated dhcp packages fix security vulnerability
Details: A badly formed packet with an invalid IPv4 UDP length field can cause an ISC DHCP server, client, or relay program to terminate abnormally (CVE-2015-8605). The dhcp package has been updated to version 4.3.3-P1, which fixes this issue and several other bugs. Also, the package has also been enhanced to provide better support for running a DHCPv6 server (mga#17177).
References: https://advisories.mageia.org/MGASA-2016-0028.html, https://bugs.mageia.org/show_bug.cgi?id=17490, https://kb.isc.org/article/AA-01334, https://kb.isc.org/article/AA-01329, https://bugs.mageia.org/show_bug.cgi?id=17177, https://bugs.mageia.org/show_bug.cgi?id=17490
Affected packages
Package
Name: dhcp
Purl: pkg:rpm/mageia/dhcp?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
