OpenPKG CVS Repository
http://cvs.openpkg.org/
____________________________________________________________________________
Server: cvs.openpkg.org Name: Ralf S. Engelschall
Root: /e/openpkg/cvs Email: [EMAIL PROTECTED]
Module: openpkg-web Date: 19-Feb-2003 15:22:47
Branch: HEAD Handle: 2003021914224700
Modified files:
openpkg-web/security OpenPKG-SA-2003.012-dhcpd.txt
Log:
final polishing and signing
Summary:
Revision Changes Path
1.2 +26 -14 openpkg-web/security/OpenPKG-SA-2003.012-dhcpd.txt
____________________________________________________________________________
patch -p0 <<'@@ .'
Index: openpkg-web/security/OpenPKG-SA-2003.012-dhcpd.txt
============================================================================
$ cvs diff -u -r1.1 -r1.2 OpenPKG-SA-2003.012-dhcpd.txt
--- openpkg-web/security/OpenPKG-SA-2003.012-dhcpd.txt 19 Feb 2003 13:48:11
-0000 1.1
+++ openpkg-web/security/OpenPKG-SA-2003.012-dhcpd.txt 19 Feb 2003 14:22:47
-0000 1.2
@@ -1,3 +1,6 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
________________________________________________________________________
OpenPKG Security Advisory The OpenPKG Project
@@ -19,24 +22,25 @@
Description:
Florian Lohoff discovered a bug [0] in dhcrelay which is part of the
- ISC DHCPD [1]. The bug is causing the relay agent to send a continuing
- packet storm towards the configured dhcp server(s) in case of a
- malicious BOOTP packet. The Common Vulnerabilities and Exposures
- (CVE) project assigned the id CAN-2003-0039 [2] to the problem.
+ ISC DHCP Distribution [1]. The bug is causing the relay agent to
+ send a continuing packet storm towards the configured DHCP server(s)
+ in case of a malicious BOOTP packet. The Common Vulnerabilities and
+ Exposures (CVE) project assigned the id CAN-2003-0039 [2] to the
+ problem.
- The update does not ultimately fix the root cause of the problem.
+ Our update does not ultimately fix the root cause of the problem.
However, it improves dhcrelay's compliance to RFC1542 [10] by
- rigorously supporting the requirements listed in section 4.1.1
- BOOTREQUEST Messages and thus limiting havoc wreaked to the network:
+ rigorously supporting the requirements listed in section "4.1.1
+ BOOTREQUEST Messages" and thus limiting havoc wreaked to the network:
- > The relay agent MUST silently discard BOOTREQUEST messages whose
- > 'hops' field exceeds the value 16. A configuration option SHOULD be
- > provided to set this threshold to a smaller value if desired by the
- > network manager. The default setting for a configurable threshold
- > SHOULD be 4.
+ "The relay agent MUST silently discard BOOTREQUEST messages whose
+ 'hops' field exceeds the value 16. A configuration option SHOULD be
+ provided to set this threshold to a smaller value if desired by the
+ network manager. The default setting for a configurable threshold
+ SHOULD be 4."
- The new configuration option is '-c', it defaults to 4, the range of
- parameter is between 0 and 16.
+ The added configuration option is named "-c". Its default value to 4
+ and the allowed range of the value is between 0 and 16.
Please check whether you are affected by running "<prefix>/bin/rpm
-q dhcpd". If you have the "dhcpd" package installed and its version
@@ -85,3 +89,11 @@
using GnuPG (http://www.gnupg.org/). For instance, pipe this message to
the command "gpg --verify --keyserver keyserver.pgp.com".
________________________________________________________________________
+
+-----BEGIN PGP SIGNATURE-----
+Comment: OpenPKG <[EMAIL PROTECTED]>
+
+iD8DBQE+U5MDgHWT4GPEy58RAu2qAKDMZ71rpxv4YgazQQw2fSi2mlfTIACfflr6
+OF+yy6uSaCRuw/RlzUVzhic=
+=kWcV
+-----END PGP SIGNATURE-----
@@ .
______________________________________________________________________
The OpenPKG Project www.openpkg.org
CVS Repository Commit List [EMAIL PROTECTED]