PT-2018-1049 · Isc+5 · Isc Dhcp+5

Felix Wilhelm

·

Published

2018-02-09

·

Updated

2025-04-25

·

CVE-2018-5733

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ISC DHCP versions 4.1.0 through 4.1-ESV-R15 ISC DHCP versions 4.2.0 through 4.2.8 ISC DHCP versions 4.3.0 through 4.3.6 ISC DHCP versions 4.4.0
Description The issue is caused by the potential overflow of a 32-bit reference counter when a malicious client sends a large amount of traffic to a DHCP server. This can cause the dhcpd service to crash, resulting in a denial of service. A remote attacker can exploit this by sending a large number of specially crafted DHCP requests, potentially exceeding a billion packets.
Recommendations For ISC DHCP versions 4.1.0 through 4.1-ESV-R15, update to a version that fixes the issue. For ISC DHCP versions 4.2.0 through 4.2.8, update to a version that fixes the issue. For ISC DHCP versions 4.3.0 through 4.3.6, update to a version that fixes the issue. For ISC DHCP versions 4.4.0, update to a version that fixes the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1300
BDU:2018-00357
CESA-2018_0469
CESA-2018_0483
CVE-2018-5733
DLA-1313-1
DSA-4133-1
MGASA-2018-0410
OPENSUSE-SU-2024:10715-1
RHSA-2018:0469
RHSA-2018:0483
RHSA-2018_0469
RHSA-2018_0483
SUSE-SU-2018:0810-1
SUSE-SU-2018:0810-2
SUSE-SU-2018:0812-1
USN-3586-1
USN-3586-2

Affected Products

Alt Linux
Centos
Isc Dhcp
Red Hat
Suse
Ubuntu