Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2774

Опубликовано: 07 мар. 2016
Источник: redhat
CVSS2: 2.6
EPSS Средний

Описание

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.

A resource-consumption flaw was discovered in the DHCP server. dhcpd did not restrict the number of open connections to OMAPI and failover ports. A remote attacker able to establish TCP connections to one of these ports could use this flaw to cause dhcpd to exit unexpectedly, stop responding requests, or exhaust system sockets (denial of service).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dhcpWill not fix
Red Hat Enterprise Linux 6dhcpWill not fix
Red Hat Enterprise Linux 7dhcpFixedRHSA-2016:259003.11.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1315259dhcp: unclosed TCP connections to OMAPI or failover ports can cause DoS

EPSS

Процентиль: 99%
0.69959
Средний

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.

CVSS3: 5.9
nvd
больше 9 лет назад

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.

CVSS3: 5.9
debian
больше 9 лет назад

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 doe ...

suse-cvrf
около 9 лет назад

Security update for dhcp

suse-cvrf
около 9 лет назад

Security update for dhcp

EPSS

Процентиль: 99%
0.69959
Средний

2.6 Low

CVSS2