cbcvebase.

Debian Isc-Dhcp vulnerabilities

30 known vulnerabilities affecting debian/isc-dhcp.

Total CVEs
30
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH16MEDIUM9LOW5

Vulnerabilities

Page 1 of 2
CVE-2011-0997P2HIGHCVSS 7.5PoCfixed in isc-dhcp 4.1.1-P1-16.1 (bookworm)2011
CVE-2011-0997 [HIGH] CVE-2011-0997: isc-dhcp - dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV... dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script. Scope: local bookworm: resolved (fixed in 4.1.1-P1-16.1) bullsey
debian
CVE-2010-2156P3MEDIUMCVSS 5.0PoCfixed in isc-dhcp 4.1.1-P1-1 (bookworm)2010
CVE-2010-2156 [MEDIUM] CVE-2010-2156: isc-dhcp - ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to ... ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID. Scope: local bookworm: resolved (fixed in 4.1.1-P1-1) bullseye: resolved (fixed in 4.1.1-P1-1) sid: resolved (fixed in 4.1.1-P1-1) trixie: resolved (fixed in 4.1.1-P1-1)
debian
CVE-2017-3144P2HIGHCVSS 7.5fixed in isc-dhcp 4.3.5-3.1 (bookworm)2017
CVE-2017-3144 [HIGH] CVE-2017-3144: isc-dhcp - A vulnerability stemming from failure to properly clean up closed OMAPI connecti... A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.
debian
CVE-2016-2774P3MEDIUMCVSS 5.9fixed in isc-dhcp 4.3.4-1 (bookworm)2016
CVE-2016-2774 [MEDIUM] CVE-2016-2774: isc-dhcp - ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not rest... ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions. Scope: local bookworm: resolved (fixed in 4.3.4-1) bullseye: resolved (fixed in 4.3.4-1) sid: res
debian
CVE-2011-2748P3HIGHCVSS 7.8fixed in isc-dhcp 4.2.2-1 (bookworm)2011
CVE-2011-2748 [HIGH] CVE-2011-2748: isc-dhcp - The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and ... The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet. Scope: local bookworm: resolved (fixed in 4.2.2-1) bullseye: resolved (fixed in 4.2.2-1) sid: resolved (fixed in 4.2.2-1) trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2011-2749P3HIGHCVSS 7.8fixed in isc-dhcp 4.2.2-1 (bookworm)2011
CVE-2011-2749 [HIGH] CVE-2011-2749: isc-dhcp - The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and ... The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet. Scope: local bookworm: resolved (fixed in 4.2.2-1) bullseye: resolved (fixed in 4.2.2-1) sid: resolved (fixed in 4.2.2-1) trixie: resolved (fixed in 4.2.2-1)
debian
CVE-2018-5733P3HIGHCVSS 7.5fixed in isc-dhcp 4.3.5-3.1 (bookworm)2018
CVE-2018-5733 [HIGH] CVE-2018-5733: isc-dhcp - A malicious client which is allowed to send very large amounts of traffic (billi... A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0. Scope: local bookworm: resolved (fixed in 4.3.5-3.1) bullseye: resolved (fixed in 4.3.5-3.
debian
CVE-2012-3571P4MEDIUMCVSS 6.1PoCfixed in isc-dhcp 4.2.4-2 (bookworm)2012
CVE-2012-3571 [MEDIUM] CVE-2012-3571: isc-dhcp - ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attacke... ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier. Scope: local bookworm: resolved (fixed in 4.2.4-2) bullseye: resolved (fixed in 4.2.4-2) sid: resolved (fixed in 4.2.4-2) trixie: resolved (fixed in 4.2.4-2)
debian
CVE-2015-8605P3MEDIUMCVSS 6.5fixed in isc-dhcp 4.3.3-7 (bookworm)2015
CVE-2015-8605 [MEDIUM] CVE-2015-8605: isc-dhcp - ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remo... ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. Scope: local bookworm: resolved (fixed in 4.3.3-7) bullseye: resolved (fixed in 4.3.3-7) sid: resolved (fixed in 4.3.3-7) trixie: resolved (fixed in 4.3.3-7)
debian
CVE-2012-4244P3HIGHCVSS 7.8fixed in bind9 1:9.8.4.dfsg-1 (bookworm)2012
CVE-2012-4244 [HIGH] CVE-2012-4244: bind9 - ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and ... ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record. Scope: local bookworm: resolved (fixed in 1:9.8.4.dfsg-1) bullseye: resolved (fixed in 1:9.8.4.dfsg-1) forky: resolv
debian
CVE-2012-5166P3HIGHCVSS 7.8fixed in bind9 1:9.8.1.dfsg.P1-4.3 (bookworm)2012
CVE-2012-5166 [HIGH] CVE-2012-5166: bind9 - ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and ... ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.3) bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-4.3) forky: resolved
debian
CVE-2012-3817P3HIGHCVSS 7.8fixed in bind9 1:9.8.1.dfsg.P1-4.2 (bookworm)2012
CVE-2012-3817 [HIGH] CVE-2012-3817: bind9 - ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; ... ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries. Scope: local bookworm: res
debian
CVE-2012-1667P3HIGHCVSS 8.5fixed in bind9 1:9.8.1.dfsg.P1-4.1 (bookworm)2012
CVE-2012-1667 [HIGH] CVE-2012-1667: bind9 - ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and ... ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record. Scope:
debian
CVE-2011-0413P3HIGHCVSS 7.8fixed in isc-dhcp 4.1.1-P1-16 (bookworm)2011
CVE-2011-0413 [HIGH] CVE-2011-0413: isc-dhcp - The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-E... The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) by sending a message over IPv6 for a declined and abandoned address. Scope: local bookworm: resolved (fixed in 4.1.1-P1-16) bullseye: resolved (fixed in
debian
CVE-2019-6470P3MEDIUMCVSS 6.5fixed in isc-dhcp 4.4.1-2 (bookworm)2019
CVE-2019-6470 [MEDIUM] CVE-2019-6470: isc-dhcp - There had existed in one of the ISC BIND libraries a bug in a function that was ... There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND librari
debian
CVE-2018-5732P3HIGHCVSS 7.5fixed in isc-dhcp 4.3.5-3.1 (bookworm)2018
CVE-2018-5732 [HIGH] CVE-2018-5732: isc-dhcp - Failure to properly bounds-check a buffer used for processing DHCP options allow... Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0 Scope:
debian
CVE-2012-2248P3HIGHCVSS 8.1fixed in isc-dhcp 4.2.4-3 (bookworm)2012
CVE-2012-2248 [HIGH] CVE-2012-2248: isc-dhcp - An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable. An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable. Scope: local bookworm: resolved (fixed in 4.2.4-3) bullseye: resolved (fixed in 4.2.4-3) sid: resolved (fixed in 4.2.4-3) trixie: resolved (fixed in 4.2.4-3)
debian
CVE-2021-25217P3HIGHCVSS 7.4fixed in isc-dhcp 4.4.1-2.3 (bookworm)2021
CVE-2021-25217 [HIGH] CVE-2021-25217: isc-dhcp - In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches o... In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially teste
debian
CVE-2012-3955P3HIGHCVSS 7.1fixed in isc-dhcp 4.2.4-2 (bookworm)2012
CVE-2012-3955 [HIGH] CVE-2012-3955: isc-dhcp - ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attacke... ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced. Scope: local bookworm: resolved (fixed in 4.2.4-2) bullseye: resolved (fixed in 4.2.4-2) sid: resolved (fixed in
debian
CVE-2012-5688P3HIGHCVSS 7.8fixed in bind9 1:9.8.4.dfsg.P1-1 (bookworm)2012
CVE-2012-5688 [HIGH] CVE-2012-5688: bind9 - ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled,... ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query. Scope: local bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-1) bullseye: resolved (fixed in 1:9.8.4.dfsg.P1-1) forky: resolved (fixed in 1:9.8.4.dfsg.P1-1) sid: resolved (fixed in 1:9
debian
Debian Isc-Dhcp vulnerabilities | cvebase