SB2016041113 - Multiple vulnerabilities in Debian Linux
Published: April 11, 2016 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Buffer overflow (CVE-ID: CVE-2012-6700)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.
2) Buffer overflow (CVE-ID: CVE-2012-6699)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.
3) Buffer overflow (CVE-ID: CVE-2012-6698)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.
Remediation
Install update from vendor's website.