ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dhcp | Aug 30, 2017 | Sep 14, 2012 |
| Centos_linux | — | Upgrade dhclientUpgrade dhcp-commonUpgrade dhcp-develUpgrade dhcp | Dec 1, 2016 | Sep 14, 2012 |
| Debian | — | Upgrade isc-dhcp | Jul 30, 2024 | Sep 14, 2012 |
| Gentoo Linux | — | Upgrade net-misc/dhcp. | Oct 30, 2017 | Sep 14, 2012 |
| Oracle Solaris | — | Upgrade service/network/dhcp/isc-dhcp to version 4.1.0.7-0.175.1.1.0.4.0 on Solaris 11.1Upgrade service/network/dhcp/isc-dhcp to version 4.1.0.7-0.175.0.13.0.3.0 on Solaris 11.0 | May 29, 2017 | Sep 14, 2012 |
| Oracle_linux | — | Upgrade dhcpUpgrade dhclientUpgrade dhcp-commonUpgrade dhcp-devel | Oct 16, 2024 | Sep 14, 2012 |
| Suse | — | Upgrade dhcp-develUpgrade dhcp-keamaUpgrade dhcpUpgrade dhcp-relayUpgrade dhcp-serverUpgrade dhcp-client | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade isc-dhcp-clientUpgrade isc-dhcp-server | Nov 8, 2024 | Sep 14, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub