PT-2013-1259 · Isc+1 · Isc Dhcp+1

Published

2013-03-28

·

Updated

2014-11-27

·

CVE-2013-2494

CVSS v2.0

4.9

Medium

VectorAV:N/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC DHCP versions 4.2.x through 4.2.5-P1 dhcp versions prior to 4.2.5 p1
Description The issue allows remote name servers to cause a denial of service, specifically memory consumption, via vectors involving a regular expression. This can be demonstrated by a memory-exhaustion attack against a machine running a dhcpd process. The exploitation of this issue may lead to disruption of protected information and can be carried out remotely by an attacker who has passed the authentication procedure.
Recommendations For ISC DHCP versions 4.2.x through 4.2.5-P1, update to version 4.2.5-P1 or later. For dhcp versions prior to 4.2.5 p1, update to version 4.2.5 p1 or later.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2398
BDU:2015-09739
CVE-2013-2494

Affected Products

Alt Linux
Isc Dhcp