PT-2012-1062 · Isc+3 · Dhcp-Common+6

Markus Hietava

·

Published

2012-07-25

·

Updated

2024-06-15

·

CVE-2012-3571

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions dhcp versions 4.1.1 through 4.2.4 dhcp versions prior to 4.1-ESV-R6 dhcp-common version 4.1.1 dhcp-devel version 4.1.1 dhclient version 4.1.1
Description The issue involves multiple vulnerabilities in the dhcp package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely, potentially causing a denial of service due to an infinite loop and CPU consumption via a malformed client identifier.
Recommendations For dhcp versions 4.1.1 through 4.2.4, update to a version later than 4.2.4 p2 to resolve the issue. For dhcp versions prior to 4.1-ESV-R6, update to 4.1-ESV-R6 or later to resolve the issue. For dhcp-common, dhcp-devel, and dhclient version 4.1.1, update to a version later than 4.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the dhcp service to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05959
BDU:2015-06086
BDU:2015-06088
BDU:2015-06089
BDU:2015-06091
BDU:2015-08873
BDU:2015-08874
BDU:2015-08875
BDU:2015-08876
BDU:2015-09699
CESA-2012_1141
CVE-2012-3571
DSA-2516-1
DSA-2519-1
DSA-2519-2
OPENSUSE-SU-2024:10358-1
RHSA-2012:1140
RHSA-2012:1141
RHSA-2012_1140
RHSA-2012_1141
SUSE-SU-2012_1003-1
SUSE-SU-2012_1005-1

Affected Products

Centos
Red Hat
Suse
Dhclient
Dhcp
Dhcp-Common
Dhcp-Devel