CVE-2011-4539

Severity
5.0MEDIUM
EPSS
26.4%
top 3.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8
Latest updateMay 13

Description

dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianisc-dhcp< 4.2.2.dfsg.1-5+2
NVDisc/dhcp12 versions+11

Also affects: Debian Linux 6.0, 7.0, Ubuntu Linux 11.04, 11.10

🔴Vulnerability Details

3
GHSA
GHSA-4mm2-hqgc-vvw9: dhcpd in ISC DHCP 42022-05-13
OSV
CVE-2011-4539: dhcpd in ISC DHCP 42011-12-08
CVEList
CVE-2011-4539: dhcpd in ISC DHCP 42011-12-08

📋Vendor Advisories

3
Ubuntu
DHCP vulnerability2011-12-15
Red Hat
dhcp: DoS due to processing certain regular expressions2011-12-07
Debian
CVE-2011-4539: isc-dhcp - dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not pro...2011

💬Community

2
Bugzilla
CVE-2011-4539 dhcp: DoS due to processing certain regular expressions [fedora-all]2011-12-09
Bugzilla
CVE-2011-4539 dhcp: DoS due to processing certain regular expressions2011-12-07