Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-25217

Опубликовано: 26 мая 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 3.3
CVSS3: 7.4

Описание

In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially tested for the vulnerability), The outcome of encountering the defect while reading a lease that will trigger it varies, according to: the component being affected (i.e., dhclient or dhcpd) whether the package was built as a 32-bit or 64-bit binary whether the compiler flag -fstack-protection-strong was used when compiling In dhclient, ISC has not successfully reproduced the error on a 64-bit system. However, on a 32-bit system it is possible to cause dhclient to crash when reading an improper lease, which could cause network connectivity problems for an affected system due to the absence of a running DHCP client process. In dh...

РелизСтатусПримечание
bionic

released

4.3.5-3ubuntu7.3
devel

released

4.4.1-2.2ubuntu7
esm-infra-legacy/trusty

not-affected

4.2.4-7ubuntu12.13+esm1
esm-infra/bionic

not-affected

4.3.5-3ubuntu7.3
esm-infra/focal

not-affected

4.4.1-2.1ubuntu5.20.04.2
esm-infra/xenial

released

4.3.3-5ubuntu12.10+esm1
focal

released

4.4.1-2.1ubuntu5.20.04.2
groovy

released

4.4.1-2.1ubuntu10.1
hirsute

released

4.4.1-2.2ubuntu6.1
impish

released

4.4.1-2.2ubuntu7

Показывать по

3.3 Low

CVSS2

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 4 лет назад

In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially tested for the vulnerability), The outcome of encountering the defect while reading a lease that will trigger it varies, according to: the component being affected (i.e., dhclient or dhcpd) whether the package was built as a 32-bit or 64-bit binary whether the compiler flag -fstack-protection-strong was used when compiling In dhclient, ISC has not successfully reproduced the error on a 64-bit system. However, on a 32-bit system it is possible to cause dhclient to crash when reading an improper lease, which could cause network connectivity problems for an affected system due to the absence of a running DHCP client process. In dh...

CVSS3: 7.4
nvd
около 4 лет назад

In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially tested for the vulnerability), The outcome of encountering the defect while reading a lease that will trigger it varies, according to: the component being affected (i.e., dhclient or dhcpd) whether the package was built as a 32-bit or 64-bit binary whether the compiler flag -fstack-protection-strong was used when compiling In dhclient, ISC has not successfully reproduced the error on a 64-bit system. However, on a 32-bit system it is possible to cause dhclient to crash when reading an improper lease, which could cause network connectivity problems for an affected system due to the absence of a running DHCP client process. In dhcpd

CVSS3: 7.4
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.4
debian
около 4 лет назад

In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other ...

suse-cvrf
почти 4 года назад

Security update for dhcp

3.3 Low

CVSS2

7.4 High

CVSS3