Описание
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a malformed DHCP response, aka internal bug 26461634.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | DNE | |
| bionic | DNE | |
| cosmic | DNE | |
| devel | not-affected | 6.10.1-1 |
| disco | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | DNE | |
| kinetic | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 6.10.1-1 |
| bionic | not-affected | 6.10.1-1 |
| cosmic | not-affected | 6.10.1-1 |
| devel | DNE | |
| disco | not-affected | 6.10.1-1 |
| esm-apps/bionic | not-affected | 6.10.1-1 |
| esm-apps/focal | not-affected | 6.10.1-1 |
| esm-apps/jammy | not-affected | 6.10.1-1 |
| esm-apps/xenial | not-affected | 6.10.1-1 |
| esm-infra-legacy/trusty | needed |
Показывать по
10 Critical
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a malformed DHCP response, aka internal bug 26461634.
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x befor ...
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a malformed DHCP response, aka internal bug 26461634.
Уязвимость свободной реализации DHCP-клиента dhcpcd, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
10 Critical
CVSS2
9.8 Critical
CVSS3