Linux suppliers tackle security holesLinux suppliers have begun releasing fixes for two critical security bugs in a networking component that could allow a denial-of-service attack or enable an attacker to take control of a system.
The problem is with the Internet Systems Consortium's Dynamic Host Configuration Protocol (DHCP) 3 application, shipped with many Linux and Unix operating system distributions as a tool for transmitting configuration information across a network.
Researchers discovered two flaws in the application that could allow a malicious user to crash systems running the DHCP server.
The bugs mean that many Unix and Linux systems will be vulnerable at least to a denial-of-service attack, and possibly to more serious threats, researchers said.