PT-2003-1081 · Isc+1 · Dhcrelay+4

Florian Lohoff

·

Publicado

2003-02-07

·

Atualizado

2017-10-10

·

CVE-2003-0039

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dhcp-3.0pl1 dhclient-3.0pl1 dhcp-devel-3.0pl1 ISC dhcrelay (dhcp-relay) versions 3.0rc9 and earlier
Description The issue concerns multiple vulnerabilities in the DHCP package of Red Hat Linux, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. The vulnerabilities can lead to a denial of service via a certain BOOTP packet that causes an infinite loop.
Recommendations For dhcp-3.0pl1, consider disabling the vulnerable DHCP service until a patch is available. For dhclient-3.0pl1, restrict access to the DHCP client to minimize the risk of exploitation. For dhcp-devel-3.0pl1, avoid using the vulnerable development package until the issue is resolved. For ISC dhcrelay (dhcp-relay) versions 3.0rc9 and earlier, consider implementing packet filtering to prevent malicious BOOTP packets from causing a denial of service.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07988
BDU:2015-07989
BDU:2015-07990
CVE-2003-0039
DSA-245

Produtos afetados

Red Hat
Dhclient
Dhcp
Dhcp-Devel
Dhcrelay