ISC.Dhclient.DHCP.Stack.Overflow

Release DateAug 25, 2009
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in ISC dhclient.

The vulnerability is caused by an error when the vulnerable software handles a malicious dhcp server response. It allows a remote attacker to execute arbitrary code via sending a crafted dhcp server response packet.
Affected ProductsDHCP 4.1 (all versions)
DHCP 4.0 (all versions)
DHCP 3.1 (all versions)
DHCP 3.0 (all versions)
DHCP 2.0 (all versions)
Recommended ActionsUpgrade to 4.1.0p1, 4.0.1p1, or 3.1.2p1.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0692
Reference/shttp://www.securityfocus.com/bid/35668 (BugTraq)
http://www.kb.cert.org/vuls/id/410676
Reference: VID-17545