Описание
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 4.3.5-3ubuntu2.2 |
| bionic | released | 4.3.5-3ubuntu5 |
| devel | released | 4.3.5-3ubuntu5 |
| esm-infra-legacy/trusty | released | 4.2.4-7ubuntu12.12 |
| esm-infra/bionic | released | 4.3.5-3ubuntu5 |
| esm-infra/xenial | released | 4.3.3-5ubuntu12.9 |
| precise/esm | not-affected | 4.1.ESV-R4-0ubuntu5.13 |
| trusty | released | 4.2.4-7ubuntu12.12 |
| trusty/esm | released | 4.2.4-7ubuntu12.12 |
| upstream | needs-triage |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
Failure to properly bounds-check a buffer used for processing DHCP opt ...
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
Уязвимость сервера ISC DHCP, связанная с переполнением буфера памяти, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к конфиденциальным данным
EPSS
5 Medium
CVSS2
7.5 High
CVSS3