Bug 601403 (CVE-2010-2156)

Summary: CVE-2010-2156 dhcp: remote DoS via zero-length client ID
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jpopelka
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: public=20100601,reported=20100607,source=cve,fedora-all/dhcp=affected/impact=moderate/cvss2=5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P/,rhel-6/dhcp=notaffected/impact=moderate/cvss2=5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P/
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-07-08 16:21:47 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 601405, 601406    
Bug Blocks:    
Attachments:
Description Flags
upstream patch to correct the issue none

Description Vincent Danen 2010-06-07 21:20:20 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2156 to
the following vulnerability:

Name: CVE-2010-2156
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2156
Assigned: 20100603
Reference: CONFIRM: http://ftp.isc.org/isc/dhcp/dhcp-4.0.2-P1-RELNOTES
Reference: CONFIRM: http://ftp.isc.org/isc/dhcp/dhcp-4.1.1-P1-RELNOTES

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote
attackers to cause a denial of service (server exit) via a zero-length
client ID.

Comment 1 Vincent Danen 2010-06-07 21:23:06 UTC
Created attachment 421951 [details]
upstream patch to correct the issue

Comment 3 Vincent Danen 2010-06-07 21:24:04 UTC
Created dhcp tracking bugs for this issue

Affects: fedora-all [bug 601405]

Comment 5 Fedora Update System 2010-06-09 09:18:13 UTC
dhcp-4.1.1-22.P1.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/dhcp-4.1.1-22.P1.fc13

Comment 6 Fedora Update System 2010-06-09 09:19:33 UTC
dhcp-4.1.1-17.P1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/dhcp-4.1.1-17.P1.fc12

Comment 9 Tomas Hoger 2010-06-09 11:18:55 UTC
Statement:

Not vulnerable. These issues did not affect the versions of dhcp as shipped with Red Hat Enterprise Linux 3, 4, or 5.

Comment 10 Fedora Update System 2010-06-15 15:56:49 UTC
dhcp-4.1.1-22.P1.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2010-06-18 12:22:30 UTC
dhcp-4.1.0p1-6.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/dhcp-4.1.0p1-6.fc11

Comment 12 Fedora Update System 2010-06-24 16:19:43 UTC
dhcp-4.1.0p1-6.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2010-06-24 16:27:33 UTC
dhcp-4.1.1-17.P1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.