openSUSE Security Update : dhcp (openSUSE-2012-71)

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

- Updated to ISC dhcp-4.2.3-P2 release, providing a DDNS
security fix: Modify the DDNS handling code. In a
previous patch we added logging code to the DDNS
handling. This code included a bug that caused it to
attempt to dereference a NULL pointer and eventually
segfault. While reviewing the code as we addressed this
problem, we determined that some of the updates to the
lease structures would not work as planned since the
structures being updated were in the process of being
freed: these updates were removed. In addition we
removed an incorrect call to the DDNS removal function
that could cause a failure during the removal of DDNS
information from the DNS server. Thanks to Jasper
Jongmans for reporting this issue. ([ISC-Bugs #27078],
CVE: CVE-2011-4868, bnc#741239)

- Removed obsolete dhcp-4.2.2-CVE-2011-4539-regex-DoS
patch.

See also :

https://bugzilla.novell.com/show_bug.cgi?id=741239

Solution :

Update the affected dhcp packages.

Risk factor :

Medium / CVSS Base Score : 6.1
(CVSS2#AV:A/AC:L/Au:N/C:N/I:N/A:C)

Family: SuSE Local Security Checks

Nessus Plugin ID: 74786 ()

Bugtraq ID:

CVE ID: CVE-2011-4539
CVE-2011-4868

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now