ITworld.com
  Search  
ITworld Home Page ITworld Webcasts ITworld White Papers ITworld Newsletters ITworld News ITworld Topics Careers ITworld Voices ITwhirled Changing the way you view IT

CERT warns of DHCP vulnerabilities

ITworld.com 1/16/03

Several potentially serious security flaws exist in the Internet Software Consortium's (ISC) DHCP (Dynamic Host Configuration Protocol) software, which is shipped as part of several operating systems, the CERT Coordination Center (CERT/CC) warned Thursday.

On this topic

In an internal audit, ISC discovered multiple buffer overflow flaws in versions 3.0 through 3.0.1RC10 of its DHCP product, according to a CERT advisory.

The flaws lie in a feature of ISC's DHCP product that allows the DHCP server to automatically update a DNS (Domain Name System) server. An attacker could take over an affected system by sending a DHCP message containing a large hostname, according to CERT.

The ISC DHCP software ships as part of products from Red Hat Inc. and SuSE Linux AG; the vulnerability status of many other vendors is still unknown, CERT said. Red Hat already has a patch available; SuSE is working on a software update, according to CERT.

DHCP software is used to automatically assign users IP (Internet Protocol) addresses when they sign on to a network. Typically a DHCP server is not accessible externally, limiting the threat of attacks.

ISC, which also provides the widely used BIND (Berkeley Internet Name Domain) DNS software, has released an update fixing the DHCP flaws. CERT maintains a list of vendors whose software could contain the ISC software and may also be vulnerable.

The CERT advisory is at: http://www.cert.org/advisories/CA-2003-01.html.




Sponsored Links

Multi-Core Test Results In Virtualized Servers
Check Out The Latest Xeon® Performance Results. Virtualized Servers vs. Non-Virtualized Servers.
FREE virus, spyware & adware scan
Find the malware your AV missed with the Sophos Threat Detection Test.
Replace your mainframe 4GL and save with Spectrum Writer.
Powerful, easy 4GL. Custom reports. Export files for PC programs. Web reports. Download free trial.
Improving the View with IP Videoconferencing
New videoconferencing technologies are poised to benefit the enterprise.
Used and Refurbished HP ProCurve Switches
Lifetime Warranties, Professional Testing & Shipping on all HP Equipment Purchases!
» Buy a link now

Advertisements
Sponsored links
Bring harmony to your mix of UNIX-Linux-Windows computing environments
Top 5 Reasons to Combine App Performance and Security
KODAK i1400 Series Scanners stand up to the challenge
Locate Hidden Software on business PCs with this free tool
 Home   Networks  General protocols  Dynamic Host Configuration Protocol (DHCP)
www.itworld.com    open.itworld.com     security.itworld.com     smallbusiness.itworld.com
storage.itworld.com     utilitycomputing.itworld.com     wireless.itworld.com

 
Contact Us   About Us   Privacy Policy    Terms of Service   Reprints  

CIO   Computerworld   CSO   GamePro   Games.net   Industry Standard   Infoworld   ITworld  
JavaWorld   LinuxWorld  MacUser   Macworld   Network World   PC World   Playlist  

DEMO   IDG Connect   IDG Knowledge Hub   IDG TechNetwork   IDG World Expo  

Copyright © Computerworld, Inc. All rights reserved

Reproduction in whole or in part in any form or medium without express written permission of Computerworld Inc. is prohibited. Computerworld and Computerworld.com and the respective logos are trademarks of International Data Group Inc.