oss-sec mailing list archives

ISC DHCP CVE-2015-8605: UDP payload length not properly checked


From: ISC Security Officer <security-officer () isc org>
Date: Tue, 12 Jan 2016 16:09:21 -0600

Please be advised that ISC publicly announced a vulnerability in the
DHCP software.

CVE-2015-8605 is a denial-of-service vector which can potentially be
exploited against ISC DHCP servers, clients, and relays.  All prior 4.x
releases of ISC DHCP are vulnerable.  Additionally, ISC DHCP 3.x may
also be vulnerable, but no testing has been done.

New releases of ISC DHCP, including security fixes for this
vulnerability, are available at: www.isc.org/downloads/

Release notes can be obtained using the following links:

ftp://ftp.isc.org/isc/dhcp/4.3.3-P1/dhcp-4.3.3-P1-RELNOTES
ftp://ftp.isc.org/isc/dhcp/4.1-ESV-R12-P1/dhcp-4.1-ESV-R12-P1-RELNOTES

-- 
Brian Conry
ISC Support
Acting Security Officer


Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: