]> code.ossystems Code Review - openembedded-core.git/commit
dhcp: CVE-2016-2774
authorCatalin Enache <catalin.enache@windriver.com>
Mon, 18 Apr 2016 12:52:16 +0000 (15:52 +0300)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 18 Apr 2016 15:27:45 +0000 (16:27 +0100)
commit2fc84114c6323bf1e3d3598af52dd1523168c9fc
tree4391a6f94785244e93e656969d0d2897b0bd88a6
parentb18134ddaf949b4f001a1613ab876aed6324040a
dhcp: CVE-2016-2774

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before
4.3.4 does not restrict the number of concurrent TCP sessions,
which allows remote attackers to cause a denial of service
(INSIST assertion failure or request-processing outage)
by establishing many sessions.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2774

Signed-off-by: Catalin Enache <catalin.enache@windriver.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-connectivity/dhcp/dhcp/CVE-2016-2774.patch [new file with mode: 0644]
meta/recipes-connectivity/dhcp/dhcp_4.3.3.bb