CERT warns of key ISC vulnerability

By Patrick Gray
16 January 2003 03:10 PM
Tags: security, suse, dhcp, isc, red hat, cert, vulnerable, ip address
CERT has warned of a serious security vulnerability in ISC's DHCP (Dynamic Host Configuration Protocol) software, which is shipped with multiple operating systems including popular Linux and BSD variants.

DHCP software is used to assign IP address information to computers on a network as they require it. For example, when a user selects "Obtain an IP address automatically" in their Windows networking settings, it's a DHCP server attached to the network that issues this IP address information to the user's computer.

It was ISC, who also maintain the popular BIND domain name server, who found the vulnerabilities.

"During an internal source code audit, developers from the ISC discovered several vulnerabilities... These vulnerabilities are stack-based buffer overflows," an advisory from CERT said.

CERT have listed known vulnerable software distributions as Red Hat 8 (The current distribution of Red Hat Linux), SuSE Linux, and BSDI, with the vulnerability status of many other vendors unknown at this stage.

This vulnerability is unlikely to expose corporate networks to any new external threats. Most networks do not allow access to DHCP services from outside, however trusted network users with access to the "soft" side of a corporate firewall may be able to exploit this vulnerability.

CERT have recommended that a patch be applied, or where that isn't possible, the DHCP service be shut down.

"As a general rule, the CERT/CC recommends disabling any service or capability that is not explicitly required. Depending on your network configuration, you may not need to use DHCP," they said.

According to the advisory, Red Hat have prepared an updated package to address the issue, SuSE are "...preparing updates, that will be released soon" and BSDI have made patches available. Some other vendors are still testing their distributions to determine their vulnerability status.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured