CVE-2018-5733
16.01.2019, 20:29
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0.Enginsight
| Vendor | Product | Version |
|---|---|---|
| isc | dhcp | 4.2.0 ≤ 𝑥 ≤ 4.2.8 |
| isc | dhcp | 4.3.0 ≤ 𝑥 ≤ 4.3.6 |
| isc | dhcp | 4.1-esv |
| isc | dhcp | 4.1-esv:r1 |
| isc | dhcp | 4.1-esv:r10 |
| isc | dhcp | 4.1-esv:r10_b1 |
| isc | dhcp | 4.1-esv:r10_rc1 |
| isc | dhcp | 4.1-esv:r11 |
| isc | dhcp | 4.1-esv:r11_b1 |
| isc | dhcp | 4.1-esv:r11_rc1 |
| isc | dhcp | 4.1-esv:r11_rc2 |
| isc | dhcp | 4.1-esv:r12 |
| isc | dhcp | 4.1-esv:r12_b1 |
| isc | dhcp | 4.1-esv:r12_p1 |
| isc | dhcp | 4.1-esv:r13 |
| isc | dhcp | 4.1-esv:r13_b1 |
| isc | dhcp | 4.1-esv:r14 |
| isc | dhcp | 4.1-esv:r14_b1 |
| isc | dhcp | 4.1-esv:r15 |
| isc | dhcp | 4.1-esv:r2 |
| isc | dhcp | 4.1-esv:r3 |
| isc | dhcp | 4.1-esv:r3_b1 |
| isc | dhcp | 4.1-esv:r4 |
| isc | dhcp | 4.1-esv:r5 |
| isc | dhcp | 4.1-esv:r5_b1 |
| isc | dhcp | 4.1-esv:r5_rc1 |
| isc | dhcp | 4.1-esv:r5_rc2 |
| isc | dhcp | 4.1-esv:r6 |
| isc | dhcp | 4.1-esv:r7 |
| isc | dhcp | 4.1-esv:r8 |
| isc | dhcp | 4.1-esv:r8_b1 |
| isc | dhcp | 4.1-esv:r8_rc1 |
| isc | dhcp | 4.1-esv:r9 |
| isc | dhcp | 4.1-esv:r9_b1 |
| isc | dhcp | 4.1-esv:r9_rc1 |
| isc | dhcp | 4.1-esv:rc1 |
| isc | dhcp | 4.1.0 |
| isc | dhcp | 4.4.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References