Input validation error in DHCP - CVE-2019-6470

 

Input validation error in DHCP - CVE-2019-6470

Published: August 20, 2019


Vulnerability identifier: #VU20341
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6470
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a double deletion issue of released addresses in the DHCPv6 code. A remote non-authenticated attacker can send specially crafted DHCP message to the affected system and perform denial of service attack.


Affected software

DHCP
Dell EMC PowerProtect Data Protection
Data Computing Appliance (DCA)
SmartFabric OS10
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse

How to mitigate CVE-2019-6470

Install updates from vendor's website.

DHCP - update to 4.4.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
Data Computing Appliance (DCA) - update to 4.3.0.0
SmartFabric OS10 - update to 10.5.6.1

External References

Related Security Bulletins