-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2003-26
http://www.turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------
Original released date : 04 Apr 2003
Last revised : 04 Apr 2003
Package : dhcp
Summary : DoS vulnerability in dhcp
More information :
When parsing malformed BOOTP packets, the relay agent will be
sending a continuing packet storm towards the configured DHCP
servers and cause dhcp(version 3) to enter an infinite loop.
Impact :
This vulerability may allow an attacker to creat a DoS condition on
the dhcp server.
Affected Products :
- Turbolinux 8 Server
- Turbolinux 8 Workstation
Solution :
Please use turbopkg tool to apply the update.
<Turbolinux 8 Server>
Source Packages
Size : MD5
dhcp-3.0pl2-3.src.rpm
878042 3dc0a46b663c5d42c7b1109bdda1410a
Binary Packages
Size : MD5
dhcp-3.0pl2-3.i586.rpm
541934 ad9df4c646c7e763e3e4dde58fbe0ba0
dhcp-client-3.0pl2-3.i586.rpm
171997 cdfe20233775d5374d9da08c60fb36c7
dhcp-devel-3.0pl2-3.i586.rpm
48096 54c0ab4f09e1773aa47264c26280f26d
<Turbolinux 8 Workstation>
Source Packages
Size : MD5
dhcp-3.0pl2-3.src.rpm
878042 a2d231f591327441663c6f7586251f8c
Binary Packages
Size : MD5
dhcp-3.0pl2-3.i586.rpm
542014 8ee35ccb301b25271bc9f423fc799788
dhcp-client-3.0pl2-3.i586.rpm
171983 648f9062b54053d72eabdac5bb1a4fa2
dhcp-devel-3.0pl2-3.i586.rpm
48098 15821ac31f30adb414ea452d0a9a75b9
References :
CVE
[
CAN-2003-0039]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=
CAN-2003-0039
--------------------------------------------------------------------------
Revision History
04 Apr 2003 Initial release
--------------------------------------------------------------------------
Copyright(C) 2003 Turbolinux, Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iD8DBQE+jOssK0LzjOqIJMwRAnlQAJ4u9xjQZuLdLMshNUhICkd6nRu5ngCgpczq
KgbMiOnwZztubtHF0KF+ONc=
=LqoT
-----END PGP SIGNATURE-----