cbcvebase.

Debian Isc-Dhcp vulnerabilities

30 known vulnerabilities affecting debian/isc-dhcp.

Total CVEs
30
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH16MEDIUM9LOW5

Vulnerabilities

Page 2 of 2
CVE-2012-5689P4HIGHCVSS 7.1fixed in bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm)2012
CVE-2012-5689 [HIGH] CVE-2012-5689: bind9 - ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configura... ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record. Scope: local bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1) bullseye: resolv
debian
CVE-2011-4539P4LOWCVSS 5.0fixed in isc-dhcp 4.2.2.dfsg.1-5 (bookworm)2011
CVE-2011-4539 [MEDIUM] CVE-2011-4539: isc-dhcp - dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not pro... dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet. Scope: local bookworm: resolved (fixed in 4.2.2.dfsg.1-5) bullseye: resolved (fixed in 4.2.2.dfsg.1-5) sid: resolved (fixed in 4.2.2.df
debian
CVE-2022-2928P4MEDIUMCVSS 6.5fixed in isc-dhcp 4.4.3-2.1 (bookworm)2022
CVE-2022-2928 [MEDIUM] CVE-2022-2928: isc-dhcp - In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the func... In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease query packets. Ea
debian
CVE-2022-2929P4MEDIUMCVSS 6.5fixed in isc-dhcp 4.4.3-2.1 (bookworm)2022
CVE-2022-2929 [MEDIUM] CVE-2022-2929: isc-dhcp - In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with ac... In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory. Scope: local bookworm: resolved (fixed in 4.4.3-2.1) bullseye: resolved (fixed in 4.4.1-2.3+deb11u1) sid: resolved (fixed in 4.4.3-2.1
debian
CVE-2009-1892P4LOWCVSS 5.0fixed in isc-dhcp 3.1.2p1-2 (bookworm)2009
CVE-2009-1892 [MEDIUM] CVE-2009-1892: isc-dhcp - dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ... dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests. Scope: local bookworm: resolved (fixed in 3.1.2p1-2) bullseye: resolved (fixed in 3.1.2p1-2) sid: resolved (fixed in 3.1.2p1-2) trixie: resolved (
debian
CVE-2012-3570P4MEDIUMCVSS 5.7fixed in isc-dhcp 4.2.4-2 (bookworm)2012
CVE-2012-3570 [MEDIUM] CVE-2012-3570: isc-dhcp - Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, ... Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fault and daemon exit) via a crafted client identifier parameter. Scope: local bookworm: resolved (fixed in 4.2.4-2) bullseye: resolved (fixed in 4.2.4-2) sid: resolved (fixed in 4.2.4-2) trixie: resolved (fixed in 4.2.4
debian
CVE-2010-3611P4MEDIUMCVSS 4.3fixed in isc-dhcp 4.1.1-P1-14 (bookworm)2010
CVE-2010-3611 [MEDIUM] CVE-2010-3611: isc-dhcp - ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allo... ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field. Scope: local bookworm: resolved (fixed in 4.1.1-P1-14) bullseye: resolved (fixed in 4.
debian
CVE-2011-4868P4LOWCVSS 6.1fixed in isc-dhcp 4.2.2.dfsg.1-5 (bookworm)2011
CVE-2011-4868 [MEDIUM] CVE-2011-4868: isc-dhcp - The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynam... The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle the DHCPv6 lease structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets related to a lease-status update. Scope: local bookworm: resolved (fi
debian
CVE-2013-2494P4LOWCVSS 7.8fixed in isc-dhcp 4.2.4-6 (bookworm)2013
CVE-2013-2494 [HIGH] CVE-2013-2494: isc-dhcp - libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a d... libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine running a dhcpd process, a related issue to CVE-2013-2266. Scope: local bookworm: resolved (fixed in 4.2.4-6) bullseye: resolved (fixed in 4.2.
debian
CVE-2012-3954P4LOWCVSS 3.3fixed in isc-dhcp 4.2.4-2 (bookworm)2012
CVE-2012-3954 [LOW] CVE-2012-3954: isc-dhcp - Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV be... Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests. Scope: local bookworm: resolved (fixed in 4.2.4-2) bullseye: resolved (fixed in 4.2.4-2) sid: resolved (fixed in 4.2.4-2) trixie: resolved (fixed in 4.2.4-2)
debian
Debian Isc-Dhcp vulnerabilities | cvebase