Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 378799 (CVE-2011-2748)

Summary: <net-misc/dhcp-4.2.2-r1: DoS (CVE-2011-{2748,2749})
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: base-system, hwoarang, petr.pisar
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.isc.org/software/dhcp/advisories/cve-2011-2748
Whiteboard: A3 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on: 362535, 380717, 380829    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2011-08-11 16:32:41 UTC
More info at $URL
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2011-08-15 07:04:26 UTC
*** Bug 379229 has been marked as a duplicate of this bug. ***
Comment 2 SpanKY gentoo-dev 2011-08-26 02:39:18 UTC
dhcp-4.2.2 now in the tree
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2011-08-26 03:27:11 UTC
(In reply to comment #2)
> dhcp-4.2.2 now in the tree

Thanks.

Arches, please test and mark stable:
=net-misc/dhcp-4.2.2
Target keywords : "alpha amd64 arm hppa ppc ppc64 s390 sh sparc x86"
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2011-08-26 09:36:21 UTC
*** Bug 374445 has been marked as a duplicate of this bug. ***
Comment 5 Thomas Kahle (RETIRED) gentoo-dev 2011-08-26 10:00:43 UTC
x86 stable
Comment 6 Opportunist 2011-08-27 07:01:13 UTC
Stable dhcp-4.2.2 doesn`t run in chroot :(

Please look at https://bugs.gentoo.org/show_bug.cgi?id=362535
Comment 7 SpanKY gentoo-dev 2011-08-27 15:41:32 UTC
we'll want to do 4.2.2-r1 since it fixes a few path related bugs no one noticed before now
Comment 8 Agostino Sarubbo gentoo-dev 2011-08-27 19:56:24 UTC
amd64 ok
Comment 9 liva 2011-08-28 10:02:57 UTC
dhcp-4.2.2-r1 doesn`t run in chroot :( 
...
Comment 10 Agostino Sarubbo gentoo-dev 2011-08-28 11:54:22 UTC
I think that bug 362535 is not a regression and it should be removed from "Depends on"
Comment 11 Markos Chandras (RETIRED) gentoo-dev 2011-08-28 11:57:25 UTC
(In reply to comment #10)
> I think that bug 362535 is not a regression and it should be removed from
> "Depends on"

It is a regressions. Version 3.X (which is the current stable) does not seem to have the same problem
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2011-09-02 17:32:25 UTC
CVE-2011-2749 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2749):
  The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3,
  and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of
  service (daemon exit) via a crafted BOOTP packet.

CVE-2011-2748 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2748):
  The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3,
  and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of
  service (daemon exit) via a crafted DHCP packet.
Comment 13 Ian Delaney (RETIRED) gentoo-dev 2011-09-07 13:53:38 UTC
amd64:

emerged, invoked, all ok
Comment 14 Markos Chandras (RETIRED) gentoo-dev 2011-09-18 11:23:26 UTC
@base-system. Can we please do 4.2.2-r1 instead? This revision seems to have fixed all the blocking issues posted in this bug
Comment 15 SpanKY gentoo-dev 2011-09-18 19:12:30 UTC
please read comment #7
Comment 16 Markos Chandras (RETIRED) gentoo-dev 2011-09-19 17:14:25 UTC
(In reply to comment #9)
> dhcp-4.2.2-r1 doesn`t run in chroot :( 
> ...

Well you need to open a separate bug and not complaining on security bugs. 4.2.2-r1 stable on amd64. Thanks Agostino and Ian
Comment 17 SpanKY gentoo-dev 2011-09-19 19:11:10 UTC
(In reply to comment #16)

chroot should be fixed in 4.2.2-r2.  if arches want to jump straight to that, it should be fine.
Comment 18 Tony Vroon (RETIRED) gentoo-dev 2011-09-20 13:36:49 UTC
+  20 Sep 2011; Tony Vroon <chainsaw@gentoo.org> dhcp-4.2.2-r2.ebuild:
+  Marked stable on AMD64 based on explicit recommendation by Markos "hwoarang"
+  Chandras in #gentoo-amd64-dev.
Comment 19 Andreas Schürch gentoo-dev 2011-09-21 13:19:48 UTC
Chroot usage seems still a bit broken with dhcp-4.2.2-r2.

Sep 21 15:03:37 localhost dhcpd: Error opening '/proc/net/dev' to list interfaces
Sep 21 15:03:37 localhost dhcpd: Can't get list of interfaces.

If i mount proc manually into the chroot before the start, i get 

Sep 21 15:11:58 localhost dhcpd: Not configured to listen on any interfaces!

Yes, it is configured in /etc/conf.d/dhcpd... But it seems to get lost on the way to the chroot!?
Comment 20 SpanKY gentoo-dev 2011-09-21 14:16:30 UTC
new issue -> new bug
Comment 21 Myckel Habets 2011-09-21 18:12:32 UTC
Builds fine on x86, rdep builds fine as well. Tested the client, no problems encountered. Ok to go for me.
Comment 22 Andreas Schürch gentoo-dev 2011-09-23 15:27:46 UTC
x86 stable. Thanks all!
Comment 23 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-09-25 10:24:00 UTC
ppc/ppc64 stable
Comment 24 Raúl Porcel (RETIRED) gentoo-dev 2011-10-02 14:47:40 UTC
alpha/arm/ia64/s390/sh/sparc stable
Comment 25 Jeroen Roovers (RETIRED) gentoo-dev 2011-10-11 16:28:54 UTC
Stable for HPPA.
Comment 26 Tim Sammut (RETIRED) gentoo-dev 2011-10-11 16:34:58 UTC
Thanks, folks. GLSA request filed.
Comment 27 GLSAMaker/CVETool Bot gentoo-dev 2013-01-09 00:53:06 UTC
This issue was resolved and addressed in
 GLSA 201301-06 at http://security.gentoo.org/glsa/glsa-201301-06.xml
by GLSA coordinator Stefan Behte (craig).