Input validation error in DHCP - CVE-2012-3955

 

Input validation error in DHCP - CVE-2012-3955

Published: September 14, 2012 / Updated: August 4, 2020


Vulnerability identifier: #VU33931
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-3955
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.


Affected software

DHCP
Amazon Linux AMI
Slackware Linux
dhcp (Alpine package)

How to mitigate CVE-2012-3955

Install update from vendor's website.

dhcp (Alpine package) - update to 4.2.4_p2-r0

External References

Related Security Bulletins