cbcvebase.
CVE-2017-3144
published 2019-01-16

CVE-2017-3144: A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the…

PriorityP260high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
72.72%
99.4th percentile
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.

Affected

21 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianisc-dhcp< isc-dhcp 4.3.5-3.1 (bookworm)isc-dhcp 4.3.5-3.1 (bookworm)
iscdhcp
iscdhcp
iscdhcp4.2.0 – 4.2.8
iscdhcp4.3.0 – 4.3.6
iscisc_dhcp
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

  • A remote attacker able to connect to the OMAPI port could use this flaw to exhaust file descriptors in the DHCP daemon, leading to a denial of service in the OMAPI functionality. Monitor for abnormal numbers of open/unclosed TCP connections to the OMAPI port on the DHCP server.
  • The vulnerability is triggered by sending an empty message over an OMAPI connection; monitor OMAPI traffic for zero-length or malformed messages that do not result in proper connection teardown.
  • Affected versions are ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6; flag unpatched DHCP server instances in this version range as vulnerable targets.
  • ·The upstream fix is available as a specific commit in the ISC DHCP git repository; patch status can be verified by checking for this commit.
  • ·Red Hat Enterprise Linux 5 and 6 packages are not affected; only RHEL 7 required patching via RHSA-2018:0158.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.