vulnerability

FreeBSD: VID-20B92374-D62A-11E9-AF73-001B217E4EE5 (CVE-2019-6474): ISC KEA -- Multiple vulnerabilities

Severity
6
CVSS
(AV:A/AC:L/Au:N/C:N/I:N/A:C)
Published
Aug 28, 2019
Added
Sep 21, 2019
Modified
Jan 22, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-20B92374-D62A-11E9-AF73-001B217E4EE5:




Internet Systems Consortium, Inc. reports:



A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate (CVE-2019-6472) [Medium]


An invalid hostname option can cause the kea-dhcp4 server to terminate (CVE-2019-6473) [Medium]


An oversight when validating incoming client requests can lead to a situation where the Kea server


will exit when trying to restart (CVE-2019-6474) [Medium]




Solution

freebsd-upgrade-package-kea
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.