PT-2011-1026 · Isc+1 · Dhcp+5

Vincent Danen

·

Published

2011-08-15

·

Updated

2024-06-15

·

CVE-2011-2748

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions dhcp versions 3.0.5 through 4.2.2 dhcp versions prior to 4.2.4 p2 dhcp-3.0.5 dhcp-3.x dhcp-4.x dhclient-3.0.5 dhcp-devel-3.0.5 libdhcp4client-3.0.5 libdhcp4client-devel-3.0.5
Description The issue is related to multiple vulnerabilities in the dhcp package, which can lead to a denial of service (daemon exit) via a crafted DHCP packet. The vulnerabilities can be exploited remotely, potentially disrupting the availability of protected information.
Recommendations For dhcp versions 3.0.5 through 4.2.2, update to version 4.2.2 or later. For dhcp versions prior to 4.2.4 p2, update to version 4.2.4 p2 or later. For dhcp-3.0.5, dhcp-3.x, dhcp-4.x, dhclient-3.0.5, dhcp-devel-3.0.5, libdhcp4client-3.0.5, and libdhcp4client-devel-3.0.5, update to a version that is not affected by the vulnerabilities. As a temporary workaround, consider restricting access to the vulnerable dhcp service until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02018
BDU:2015-06085
BDU:2015-06087
BDU:2015-06090
BDU:2015-06112
BDU:2015-06113
BDU:2015-08760
BDU:2015-08761
BDU:2015-08762
BDU:2015-08763
BDU:2015-09699
CVE-2011-2748
DSA-2292-1
OPENSUSE-SU-2024:10358-1
RHSA-2011:1160
RHSA-2011_1160

Affected Products

Red Hat
Dhclient
Dhcp
Dhcp-Devel
Libdhcp4Client
Libdhcp4Client-Devel