ALAS-2016-637

Related Vulnerabilities: CVE-2015-8605  

ISC DHCP 4.x before 4.1-ESV-R12-P1 and 4.2.x and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.

ALAS-2016-637


Amazon Linux AMI Security Advisory: ALAS-2016-637
Advisory Release Date: 2016-01-18 11:00 Pacific
Advisory Updated Date: 2016-01-18 11:00 Pacific
Severity: Medium
References: CVE-2015-8605 

Issue Overview:

ISC DHCP 4.x before 4.1-ESV-R12-P1 and 4.2.x and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.


Affected Packages:

dhcp


Issue Correction:
Run yum update dhcp to update your system.

New Packages:
i686:
    dhcp-debuginfo-4.1.1-43.P1.22.amzn1.i686
    dhcp-devel-4.1.1-43.P1.22.amzn1.i686
    dhcp-common-4.1.1-43.P1.22.amzn1.i686
    dhcp-4.1.1-43.P1.22.amzn1.i686
    dhclient-4.1.1-43.P1.22.amzn1.i686

src:
    dhcp-4.1.1-43.P1.22.amzn1.src

x86_64:
    dhcp-common-4.1.1-43.P1.22.amzn1.x86_64
    dhclient-4.1.1-43.P1.22.amzn1.x86_64
    dhcp-devel-4.1.1-43.P1.22.amzn1.x86_64
    dhcp-4.1.1-43.P1.22.amzn1.x86_64
    dhcp-debuginfo-4.1.1-43.P1.22.amzn1.x86_64