openSUSE Security Update : dhcp (openSUSE-2012-71)
Medium Nessus Plugin ID 74786
SynopsisThe remote openSUSE host is missing a security update.
Description- Updated to ISC dhcp-4.2.3-P2 release, providing a DDNS security fix: Modify the DDNS handling code. In a previous patch we added logging code to the DDNS handling. This code included a bug that caused it to attempt to dereference a NULL pointer and eventually segfault. While reviewing the code as we addressed this problem, we determined that some of the updates to the lease structures would not work as planned since the structures being updated were in the process of being freed: these updates were removed. In addition we removed an incorrect call to the DDNS removal function that could cause a failure during the removal of DDNS information from the DNS server. Thanks to Jasper Jongmans for reporting this issue. ([ISC-Bugs #27078], CVE: CVE-2011-4868, bnc#741239)
- Removed obsolete dhcp-4.2.2-CVE-2011-4539-regex-DoS patch.
SolutionUpdate the affected dhcp packages.