PT-2011-1204 · Isc+2 · Dhcp+2

Publicado

2011-12-08

·

Atualizado

2024-06-15

·

CVE-2011-4539

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions dhcp versions prior to 4.2.4 p2 ISC DHCP 4.x versions prior to 4.2.3-P1 ISC DHCP 4.1-ESV versions prior to 4.1-ESV-R4
Description The issue is related to multiple vulnerabilities in the dhcp package, which can be exploited remotely, leading to a denial of service and potentially disrupting the availability of protected information. Specifically, the dhcpd in ISC DHCP does not properly handle regular expressions in dhcpd.conf, allowing remote attackers to cause a daemon crash via a crafted request packet.
Recommendations For dhcp versions prior to 4.2.4 p2, update to version 4.2.4 p2 or later to resolve the issue. For ISC DHCP 4.x versions prior to 4.2.3-P1, update to version 4.2.3-P1 or later to resolve the issue. For ISC DHCP 4.1-ESV versions prior to 4.1-ESV-R4, update to version 4.1-ESV-R4 or later to resolve the issue. As a temporary workaround, consider restricting access to the dhcpd.conf file to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09699
CESA-2011_1819
CVE-2011-4539
DSA-2519-1
DSA-2519-2
OPENSUSE-SU-2024:10358-1
RHSA-2011:1819
RHSA-2011_1819

Produtos afetados

Centos
Red Hat
Dhcp