ISC DHCP 4.1-ESV-R6 is now available

Shawn Routhier <[email protected]> Tue, 24 Jul 2012 11:22:37 -0700
Newsgroups gmane.network.dhcp.isc.announce
Message-ID <[email protected]>
--===============4353566341438740565==
Content-Type: multipart/alternative; boundary="Apple-Mail=_7FF42748-622D-45F9-8A35-75041AEA6CC1"


--Apple-Mail=_7FF42748-622D-45F9-8A35-75041AEA6CC1
Content-Transfer-Encoding: 7bit
Content-Type: text/plain;
	charset=us-ascii

ISC DHCP 4.1-ESV-R6 is now available for download.

This is a production release of 4.1-ESV-R6, a maintenance release
that includes several security patches as well as some bug fixes.

The security advisories can be found at:
https://kb.isc.org/article/AA-00712
https://kb.isc.org/article/AA-00737

A list of the changes in this release has been appended to the end
of this message.  For a complete list of changes from any previous
release, please consult the RELNOTES file within the source
distribution, or on our website:

http://www.isc.org/software/dhcp/41-esv-r6

This release, and its OpenPGP-signatures are available now from:

    ftp://ftp.isc.org/isc/dhcp/4.1-ESV-R6/dhcp-4.1-ESV-R6.tar.gz
    ftp://ftp.isc.org/isc/dhcp/4.1-ESV-R6/dhcp-4.1-ESV-R6.tar.gz.sha512.asc
    ftp://ftp.isc.org/isc/dhcp/4.1-ESV-R6/dhcp-4.1-ESV-R6.tar.gz.sha256.asc
    ftp://ftp.isc.org/isc/dhcp/4.1-ESV-R6/dhcp-4.1-ESV-R6.tar.gz.sha1.asc

ISC's Release Signing Key can be obtained at:

    http://www.isc.org/about/openpgp/

                        Changes since 4.1-ESV-R5

- Correct code to calculate timing values in client to compare
  rebind value to infinity instead of renew value.
  Thanks to Chenda Huang from H3C Technologies Co., Limited
  for reporting this issue.
  [ISC-Bugs #29062]

- Fix some issues in the code for parsing and printing options.
  [ISC-Bugs #22625] - properly print options that have several fields
  followed by an array of something for example "fIa"
  [ISC-Bugs #27289] - properly parse options in declarations that have
  several fields followed by an array of something for example "fIa"
  [ISC-Bugs #27296] - properly determine if we parsed a 16 or 32 bit
  value in evaluate_numeric_expression (extract-int).
  [ISC-Bugs #27314] - properly parse a zero length option from
  a lease file.  Thanks to Marius Tomaschewski from SUSE for the report
  and prototype patch for this ticket as well as ticket 27289.

! Previously the server code was relaxed to allow packets with zero
  length client ids to be processed.  Under some situations use of
  zero length client ids can cause the server to go into an infinite
  loop.  As such ids are not valid according to RFC 2132 section 9.14
  the server no longer accepts them.  Client ids with a length of 1
  are also invalid but the server still accepts them in order to
  minimize disruption.  The restriction will likely be tightened in
  the future to disallow ids with a length of 1.
  Thanks to Markus Hietava of Codenomicon CROSS project for the
  finding this issue and CERT-FI for vulnerability coordination.
  [ISC-Bugs #29851]
  CVE: CVE-2012-3571

! A pair of memory leaks were found and fixed.  Thanks to
  Glen Eustace of Massey University, New Zealand for finding
  this issue.
  [ISC-Bugs #30024]
  CVE: CVE-2012-3954


--Apple-Mail=_7FF42748-622D-45F9-8A35-75041AEA6CC1
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">ISC =
DHCP 4.1-ESV-R6 is now available for download.<div><br></div><div>This =
is a production release of 4.1-ESV-R6, a maintenance =
release</div><div>that includes several security patches as well as some =
bug fixes.</div><div><br></div><div>The security advisories can be found =
at:</div><div><a =
href=3D"https://kb.isc.org/article/AA-00712">https://kb.isc.org/article/AA=
-00712</a></div><div><a =
href=3D"https://kb.isc.org/article/AA-00737">https://kb.isc.org/article/AA=
-00737</a></div><div><br></div><div><div>A list of the changes in this =
release has been appended to the end</div><div>of this message. =
&nbsp;For a complete list of changes from any =
previous</div><div>release, please consult the RELNOTES file within the =
source</div><div>distribution, or on our =
website:</div><div><br></div><div><a =
href=3D"http://www.isc.org/software/dhcp/41-esv-r6">http://www.isc.org/sof=
tware/dhcp/41-esv-r6</a></div><div><br></div><div>This release, and its =
OpenPGP-signatures are available now =
from:</div><div><br></div><div>&nbsp; &nbsp;&nbsp;<a =
href=3D"ftp://ftp.isc.org/isc/dhcp/4.1-ESV-R6/dhcp-4.1-ESV-R6.tar.gz">ftp:=
//ftp.isc.org/isc/dhcp/4.1-ESV-R6/dhcp-4.1-ESV-R6.tar.gz</a></div><div>&nb=
sp; &nbsp;&nbsp;<a =
href=3D"ftp://ftp.isc.org/isc/dhcp/">ftp://ftp.isc.org/isc/dhcp/</a>4.1-ES=
V-R6/dhcp-4.1-ESV-R6.tar.gz.sha512.asc</div><div>&nbsp; &nbsp;&nbsp;<a =
href=3D"ftp://ftp.isc.org/isc/dhcp/">ftp://ftp.isc.org/isc/dhcp/</a>4.1-ES=
V-R6/dhcp-4.1-ESV-R6.tar.gz.sha256.asc</div><div>&nbsp; &nbsp;&nbsp;<a =
href=3D"ftp://ftp.isc.org/isc/dhcp/">ftp://ftp.isc.org/isc/dhcp/</a>4.1-ES=
V-R6/dhcp-4.1-ESV-R6.tar.gz.sha1.asc</div><div><br></div><div>ISC's =
Release Signing Key can be obtained at:</div><div><br></div><div>&nbsp; =
&nbsp;&nbsp;<a =
href=3D"http://www.isc.org/about/openpgp/">http://www.isc.org/about/openpg=
p/</a></div></div><div><br></div><div><div>&nbsp; &nbsp; &nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Changes since =
4.1-ESV-R5</div><div><br></div><div>- Correct code to calculate timing =
values in client to compare</div><div>&nbsp; rebind value to infinity =
instead of renew value.</div><div>&nbsp; Thanks to Chenda Huang from H3C =
Technologies Co., Limited</div><div>&nbsp; for reporting this =
issue.</div><div>&nbsp; [ISC-Bugs #29062]</div><div><br></div><div>- Fix =
some issues in the code for parsing and printing =
options.</div><div>&nbsp; [ISC-Bugs #22625] - properly print options =
that have several fields</div><div>&nbsp; followed by an array of =
something for example "fIa"</div><div>&nbsp; [ISC-Bugs #27289] - =
properly parse options in declarations that have</div><div>&nbsp; =
several fields followed by an array of something for example =
"fIa"</div><div>&nbsp; [ISC-Bugs #27296] - properly determine if we =
parsed a 16 or 32 bit</div><div>&nbsp; value in =
evaluate_numeric_expression (extract-int).</div><div>&nbsp; [ISC-Bugs =
#27314] - properly parse a zero length option from</div><div>&nbsp; a =
lease file. &nbsp;Thanks to Marius Tomaschewski from SUSE for the =
report</div><div>&nbsp; and prototype patch for this ticket as well as =
ticket 27289.</div><div><br></div><div>! Previously the server code was =
relaxed to allow packets with zero</div><div>&nbsp; length client ids to =
be processed. &nbsp;Under some situations use of</div><div>&nbsp; zero =
length client ids can cause the server to go into an =
infinite</div><div>&nbsp; loop. &nbsp;As such ids are not valid =
according to RFC 2132 section 9.14</div><div>&nbsp; the server no longer =
accepts them. &nbsp;Client ids with a length of 1</div><div>&nbsp; are =
also invalid but the server still accepts them in order =
to</div><div>&nbsp; minimize disruption. &nbsp;The restriction will =
likely be tightened in</div><div>&nbsp; the future to disallow ids with =
a length of 1.</div><div>&nbsp; Thanks to Markus Hietava of Codenomicon =
CROSS project for the</div><div>&nbsp; finding this issue and CERT-FI =
for vulnerability coordination.</div><div>&nbsp; [ISC-Bugs =
#29851]</div><div>&nbsp; CVE: CVE-2012-3571</div><div><br></div><div>! A =
pair of memory leaks were found and fixed. &nbsp;Thanks =
to</div><div>&nbsp; Glen Eustace of Massey University, New Zealand for =
finding</div><div>&nbsp; this issue.</div><div>&nbsp; [ISC-Bugs =
#30024]</div><div>&nbsp; CVE: =
CVE-2012-3954</div></div><div><br></div></body></html>=

--Apple-Mail=_7FF42748-622D-45F9-8A35-75041AEA6CC1--

--===============4353566341438740565==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dhcp-announce mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/dhcp-announce
--===============4353566341438740565==--