ISC DHCP vuln - update available
- https://www.isc.org/node/472
14 July 2009 - "ISC Releases patches to address security vulnerability. Download patches today*.
ISC dhclient has a stack overflow vulnerability which makes it theoretically possible for a rogue DHCP server to execute arbitrary commands as root on the affected system through stack return subversion…"
* https://www.isc.org/downloadables/12
Vuln in dhclient - Check Your Vendor For Patches
- http://isc.sans.org/diary.html?storyid=6850
Last Updated: 2009-07-22 20:26:01 UTC - "US-Cert released VU#410676* which deals with a vulnerability in the ISC DHCP dhclient application. "The ISC DHCP client code (dhclient) contains a stack buffer overflow in the script_write_params() method. dhclient fails to check the length of the server-supplied subnet-mask option before copying it into a buffer. According to ISC, the following versions are affected:
DHCP 4.1 (all versions)
DHCP 4.0 (all versions)
DHCP 3.1 (all versions)
DHCP 3.0 (all versions)
DHCP 2.0 (all versions)"
Red Hat (no version specified) and Ubuntu are known vulnerable. More details are available at * http://www.kb.cert.org/vuls/id/410676 , https://www.isc.org/node/468 and http://vrt-sourcefire.blogspot.com/2009/07…-this-post.html "
ISC DHCPv6 vuln/fix - upgrade to 4.1.2-P1, 4.1-ESV-R1, or 4.2.1b1
- http://www.securitytracker.com/id/1024999
Jan 28 2011 - "A remote user can send specially crafted message for an address that was previously declined and internally tagged as abandoned to trigger an assert failure and cause the target DHCPv6 service to crash. DHCPv4 servers are not affected.
Impact: A remote user can cause the target service to crash.
Solution: The vendor has issued a fix (4.1.2-P1, 4.1-ESV-R1, or 4.2.1b1).
The vendor's advisory is available at:
Vendor URL: http://www.isc.org/software/dhcp/advisories/cve-2011-0413
"… Solution: Upgrade to 4.1.2-P1, 4.1-ESV-R1, or 4.2.1b1…"
ISC DHCP Memory Leak …
- http://www.securitytracker.com/id/1027300
CVE Reference: http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2012-3954 - 3.3
Jul 25 2012
Description: A vulnerability was reported in ISC DHCP. A remote user on the local network can cause denial of service conditions.
Impact: A remote user on the local network can consume excessive memory resources on the target system.
Solution: The vendor has issued a fix (4.1-ESV-R6, 4.2.4-P1).
The vendor's advisory is available at: https://kb.isc.org/article/AA-00737
Severity: Medium
ISC DHCP Client Identifier Infinite Loop …
- http://www.securitytracker.com/id/1027299
CVE Reference: http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2012-3571 - 6.1
Jul 25 2012
Description: A vulnerability was reported in ISC DHCP. A remote user on the local network can cause denial of service conditions.
Impact: A remote user on the local network can cause the target service to consume excessive CPU resources on the target system.
Solution: The vendor has issued a fix (4.1-ESV-R6, 4.2.4-P1).
The vendor's advisory is available at: https://kb.isc.org/article/AA-00712
Severity: High
ISC DHCP Client Identifier Buffer Overflow …
- http://www.securitytracker.com/id/1027298
CVE Reference: http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2012-3570 - 6.1
Jul 25 2012
Description: A vulnerability was reported in ISC DHCP. A remote user on the local network can cause denial of service conditions…
Impact: A remote user on the local network can cause the target service to crash.
Solution: The vendor has issued a fix (4.2.4-P1).
The vendor's advisory is available at: https://kb.isc.org/article/AA-00714
Severity: High
___
ISC DHCP
- http://atlas.arbor.net/briefs/index#-3966106
Severity: Elevated Severity
July 30, 2012
Local users can cause a denial of service on the ISC DHCP server. Exploit code has been released for this vulnerability. Analysis: … An attacker could use this for a simple DoS to keep systems from obtaining new leases or to keep the DHCP server from offering new leases. In the event that the DHCP server is down, an attacker could spoof DHCP responses and hand out malicious information. Malware has performed DHCP spoofing in order to redirect users through a compromised host in an attempt to spread the infection.
Source: http://seclists.org/fulldisclosure/2012/Jul/372