PT-2011-1026 · Isc+1 · Dhcp+5

Vincent Danen

·

Publicado

2011-08-15

·

Atualizado

2024-06-15

·

CVE-2011-2748

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions dhcp versions 3.0.5 through 4.2.2 dhcp versions prior to 4.2.4 p2 dhcp-3.0.5 dhcp-3.x dhcp-4.x dhclient-3.0.5 dhcp-devel-3.0.5 libdhcp4client-3.0.5 libdhcp4client-devel-3.0.5
Description The issue is related to multiple vulnerabilities in the dhcp package, which can lead to a denial of service (daemon exit) via a crafted DHCP packet. The vulnerabilities can be exploited remotely, potentially disrupting the availability of protected information.
Recommendations For dhcp versions 3.0.5 through 4.2.2, update to version 4.2.2 or later. For dhcp versions prior to 4.2.4 p2, update to version 4.2.4 p2 or later. For dhcp-3.0.5, dhcp-3.x, dhcp-4.x, dhclient-3.0.5, dhcp-devel-3.0.5, libdhcp4client-3.0.5, and libdhcp4client-devel-3.0.5, update to a version that is not affected by the vulnerabilities. As a temporary workaround, consider restricting access to the vulnerable dhcp service until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02018
BDU:2015-06085
BDU:2015-06087
BDU:2015-06090
BDU:2015-06112
BDU:2015-06113
BDU:2015-08760
BDU:2015-08761
BDU:2015-08762
BDU:2015-08763
BDU:2015-09699
CVE-2011-2748
DSA-2292-1
OPENSUSE-SU-2024:10358-1
RHSA-2011:1160
RHSA-2011_1160

Produtos afetados

Red Hat
Dhclient
Dhcp
Dhcp-Devel
Libdhcp4Client
Libdhcp4Client-Devel