Debian Security Advisory

DSA-2184-1 isc-dhcp -- denial of service

Date Reported:
05 Mar 2011
Affected Packages:
isc-dhcp
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 611217.
In Mitre's CVE dictionary: CVE-2011-0413.
More information:

It was discovered that the ISC DHCPv6 server does not correctly process requests which come from unexpected source addresses, leading to an assertion failure and a daemon crash.

The oldstable distribution (lenny) is not affected by this problem.

For the stable distribution (squeeze), this problem has been fixed in version 4.1.1-P1-15+squeeze1.

For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 4.1.1-P1-16.

We recommend that you upgrade your isc-dhcp packages.