Input validation error in DHCP - CVE-2015-8605
Published: January 15, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32355
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8605
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
Affected software
DHCP
Amazon Linux AMI
Slackware Linux
Fedora
dhcp (Alpine package)
dhcp
Integrated Management Module II (IMM2)
Amazon Linux AMI
Slackware Linux
Fedora
dhcp (Alpine package)
dhcp
Integrated Management Module II (IMM2)
How to mitigate CVE-2015-8605
Install update from vendor's website.
dhcp (Alpine package) - update to 4.3.3_p1-r0
Integrated Management Module II (IMM2) - update to 1AOO76I-6.00
dhcp - addressed in versions 4.3.2-7.fc22, 4.3.3-8.P1.fc23
Integrated Management Module II (IMM2) - update to 1AOO76I-6.00
dhcp - addressed in versions 4.3.2-7.fc22, 4.3.3-8.P1.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175594.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176031.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00162.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00168.html
- http://www.debian.org/security/2016/dsa-3442
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.securityfocus.com/bid/80703
- http://www.securitytracker.com/id/1034657
- http://www.ubuntu.com/usn/USN-2868-1
- https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/
- https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/
- https://kb.isc.org/article/AA-01334
Related Security Bulletins
- Input validation error in ISC Dhcp
- Input validation error in dhcp (Alpine package)
- Amazon Linux AMI update for dhcp
- Slackware Linux update for dhcp
- Input validation error in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems
- Fedora 22 update for dhcp
- Fedora 23 update for dhcp