PT-2018-1048 · Isc+5 · Isc Dhcp+5

Published

2017-08-31

·

Updated

2024-06-15

·

CVE-2018-5732

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC DHCP versions 4.1.0 through 4.1-ESV-R15 ISC DHCP versions 4.2.0 through 4.2.8 ISC DHCP versions 4.3.0 through 4.3.6 ISC DHCP versions 4.4.0
Description The issue is related to a buffer overflow in the dhclient due to insufficient bounds checking of a buffer used for processing DHCP options. This can be exploited by a malicious server or an entity masquerading as a server, which sends a response containing a specially constructed options section, potentially causing a crash or allowing for the execution of arbitrary code.
Recommendations For ISC DHCP versions 4.1.0 through 4.1-ESV-R15, update to a version outside of this range to resolve the issue. For ISC DHCP versions 4.2.0 through 4.2.8, update to a version outside of this range to resolve the issue. For ISC DHCP versions 4.3.0 through 4.3.6, update to a version outside of this range to resolve the issue. For ISC DHCP version 4.4.0, update to a version outside of this range to resolve the issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2138
ALT-PU-2018-1300
BDU:2018-00356
CESA-2018_0469
CESA-2018_0483
CVE-2018-5732
DLA-1313-1
DSA-4133-1
MGASA-2018-0410
OPENSUSE-SU-2024:10715-1
RHSA-2018:0469
RHSA-2018:0483
RHSA-2018_0469
RHSA-2018_0483
SUSE-SU-2018:0810-1
SUSE-SU-2018:0810-2
SUSE-SU-2018:0812-1
SUSE-SU-2018_0810-1
SUSE-SU-2018_0810-2
SUSE-SU-2018_0812-1
USN-3586-1
USN-3586-2

Affected Products

Alt Linux
Centos
Isc Dhcp
Red Hat
Suse
Ubuntu