[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 362-1] dhcpcd security update

Package        : dhcpcd
Version        : 1:3.2.3-5+squeeze2
CVE ID         : CVE-2012-6698 CVE-2012-6699 CVE-2012-6700

Guido Vranken discovered several memory-related vulnerabilities
while fuzzing DHCP messages sent to dhcpcd.

For Debian 6 “Squeeze”, those issues have been fixed in version


    Out-of-bounds write with specially crafted DHCP messages.


    Out-of-bounds read with specially crafted DHCP messages.


    Use after free with specially crafted DHCP messages.

Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/

Attachment: signature.asc
Description: PGP signature

Reply to: