Advisories ยป MGASA-2017-0458

Updated dhcp packages fix security vulnerability

Publication date: 21 Dec 2017
Modification date: 17 Jan 2018
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-3144

Description

It was found that the DHCP daemon does not free socket descriptors when
handling empty OMAPI messages. An adjacent network attacker could
potentially use this flaw to send crafted OMAPI messages to the DHCP
daemon, thereby leading to denial of service due to exhaustion of file
descriptors in the DHCP daemon process.
                

References

SRPMS

5/core

6/core