Debian Security Advisory
DLA-1908-1 pump -- LTS security update
- Date Reported:
- 02 Sep 2019
- Affected Packages:
- pump
- Vulnerable:
- Yes
- Security database references:
- No other external database security references currently available.
- More information:
-
It was discovered that there was an arbitrary code execution vulnerability in the pump DHCP/BOOTP client.
When copying the body of the server response, the ethernet packet length could be forged leading to being able to overwrite stack memory. Thanks to <ltspro2@secmail.pro> for the report and patch. (#933674)
For Debian 8
Jessie
, these problems have been fixed in version 0.8.24-7+deb8u1.We recommend that you upgrade your pump packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
