MGASA-2017-0458
Dashboard / Vulnerabilities / MGASA-2017-0458
Summary: Updated dhcp packages fix security vulnerability
Details: It was found that the DHCP daemon does not free socket descriptors when handling empty OMAPI messages. An adjacent network attacker could potentially use this flaw to send crafted OMAPI messages to the DHCP daemon, thereby leading to denial of service due to exhaustion of file descriptors in the DHCP daemon process.
References: https://advisories.mageia.org/MGASA-2017-0458.html, https://bugs.mageia.org/show_bug.cgi?id=22204, https://lists.fedoraproject.org/archives/list/[email protected]/thread/UJCMW5N3YHQ7WCRPR2QZBKJZBVJUZ6LG/, https://kb.isc.org/article/AA-01541
Affected packages
Package
Name: dhcp
Purl: pkg:rpm/mageia/dhcp?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
