CVE-2009-1892: DoS

Related Vulnerabilities: CVE-2009-1892  

Debian Bug report logs - #539492
CVE-2009-1892: DoS

version graph

Package: dhcp3-server; Maintainer for dhcp3-server is (unknown);

Reported by: Steffen Joeris <steffen.joeris@skolelinux.de>

Date: Sat, 1 Aug 2009 12:45:02 UTC

Severity: grave

Tags: patch, security

Fixed in version 3.1.2p1-2

Done: Andrew Pollock <apollock@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Andrew Pollock <apollock@debian.org>:
Bug#539492; Package dhcp3-server. (Sat, 01 Aug 2009 12:45:05 GMT) (full text, mbox, link).


Acknowledgement sent to Steffen Joeris <steffen.joeris@skolelinux.de>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Andrew Pollock <apollock@debian.org>. (Sat, 01 Aug 2009 12:45:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Steffen Joeris <steffen.joeris@skolelinux.de>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2009-1892: DoS
Date: Sat, 01 Aug 2009 22:42:50 +1000
[Message part 1 (text/plain, inline)]
Package: dhcp3-server
Severity: grave
Tags: security patch

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for dhcp3.

CVE-2009-1892[0]:
| dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and
| hardware ethernet configuration settings are both used, allows remote
| attackers to cause a denial of service (daemon crash) via unspecified
| requests.

The patch that was used for the DSA is attached.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

Cheers
Steffen

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1892
    http://security-tracker.debian.net/tracker/CVE-2009-1892
[server-clientid-crash.dpatch (text/x-shellscript, attachment)]

Bug 539492 cloned as bug 549584. Request was from Giuseppe Iuculano <giuseppe@iuculano.it> to control@bugs.debian.org. (Sun, 04 Oct 2009 14:51:01 GMT) (full text, mbox, link).


Reply sent to Andrew Pollock <apollock@debian.org>:
You have taken responsibility. (Thu, 08 Oct 2009 15:06:15 GMT) (full text, mbox, link).


Notification sent to Steffen Joeris <steffen.joeris@skolelinux.de>:
Bug acknowledged by developer. (Thu, 08 Oct 2009 15:06:16 GMT) (full text, mbox, link).


Message #12 received at 539492-done@bugs.debian.org (full text, mbox, reply):

From: Andrew Pollock <apollock@debian.org>
To: 539492-done@bugs.debian.org
Subject: Fixed in 3.1.2p1-2
Date: Fri, 9 Oct 2009 00:47:08 +1000
[Message part 1 (text/plain, inline)]
Version: 3.1.2p1-2

This was fixed in 3.1.2p1-2
[signature.asc (application/pgp-signature, inline)]

Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 06 Nov 2009 07:46:04 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:36:48 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.