CVE-2009-1892Dhcp vulnerability

CWE-168 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
6.7%
top 8.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17
Latest updateMay 2

Description

dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDisc/dhcp5 versions+4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q526-8q52-r7jc: dhcpd in ISC DHCP 32022-05-02
CVEList
CVE-2009-1892: dhcpd in ISC DHCP 32009-07-17
OSV
CVE-2009-1892: dhcpd in ISC DHCP 32009-07-17

📋Vendor Advisories

2
Red Hat
dhcp: DoS/abort in some configs with client-identifier and hardware address host specifications2009-07-14
Debian
CVE-2009-1892: isc-dhcp - dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ...2009

💬Community

2
Bugzilla
CVE-2009-1892 dhcp: DoS/abort in some configs with client-identifier and hardware address host specifications2009-07-15
Bugzilla
CVE-2009-1892 dhcp: DoS/abort in some configs with client-identifier and hardware address host specifications2009-07-06
CVE-2009-1892 — ISC Dhcp vulnerability | cvebase