dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dhclientUpgrade dhcp-develUpgrade dhcpUpgrade dhcp-common | Dec 1, 2016 | Dec 8, 2011 |
| Debian | — | Upgrade isc-dhcp | Jul 30, 2024 | Dec 8, 2011 |
| Freebsd | — | Upgrade isc-dhcp42-serverUpgrade isc-dhcp41-server | Dec 10, 2025 | Dec 7, 2011 |
| Gentoo Linux | — | Upgrade net-misc/dhcp. | Oct 30, 2017 | Dec 8, 2011 |
| Oracle Solaris | — | Upgrade service/network/dhcp/isc-dhcp to version 4.1.0.4-0.175.0.4.0.5.0 on Solaris 11.0 | May 29, 2017 | Dec 8, 2011 |
| Oracle_linux | — | Upgrade dhcp-commonUpgrade dhcp-develUpgrade dhclientUpgrade dhcp | Oct 16, 2024 | Dec 8, 2011 |
| Suse | — | Upgrade dhcp-keamaUpgrade dhcp-develUpgrade dhcpUpgrade dhcp-relayUpgrade dhcp-serverUpgrade dhcp-client | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade isc-dhcp-server | Nov 8, 2024 | Dec 8, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub