Debian Security Advisory

DLA-1908-1 pump -- LTS security update

Date Reported:
02 Sep 2019
Affected Packages:
pump
Vulnerable:
Yes
Security database references:
No other external database security references currently available.
More information:

It was discovered that there was an arbitrary code execution vulnerability in the pump DHCP/BOOTP client.

When copying the body of the server response, the ethernet packet length could be forged leading to being able to overwrite stack memory. Thanks to <ltspro2@secmail.pro> for the report and patch. (#933674)

For Debian 8 Jessie, these problems have been fixed in version 0.8.24-7+deb8u1.

We recommend that you upgrade your pump packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS