Search CVE reports


Toggle filters

41 – 50 of 75 results


CVE-2018-5732

Medium priority
Fixed

Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a...

1 affected package

isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-dhcp Fixed
Show less packages

CVE-2017-3144

Low priority
Fixed

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8,...

1 affected package

isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-dhcp Fixed Fixed
Show less packages

CVE-2016-2774

Low priority

Some fixes available 2 of 6

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing...

1 affected package

isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-dhcp Not affected Not affected
Show less packages

CVE-2016-1504

Medium priority
Vulnerable

dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.

2 affected packages

dhcpcd5, dhcpcd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd5 Not in release Not affected Not affected Not affected
dhcpcd Not affected Not in release Not in release Not in release
Show less packages

CVE-2016-1503

Medium priority
Vulnerable

dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or...

2 affected packages

dhcpcd5, dhcpcd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd5 Not in release Not affected Not affected Not affected
dhcpcd Not affected Not in release Not in release Not in release
Show less packages

CVE-2015-8605

Medium priority
Fixed

ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.

1 affected package

isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-dhcp
Show less packages

CVE-2014-7913

Medium priority
Vulnerable

The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android before 5.1 and other products, misinterprets the return value of the snprintf function, which allows remote DHCP...

2 affected packages

dhcpcd, dhcpcd5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Not affected Not in release Not in release Not in release
dhcpcd5 Not in release Not affected Not affected Not affected
Show less packages

CVE-2014-7912

Medium priority
Vulnerable

The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products, does not validate the relationship between length fields and the amount of data, which allows remote DHCP...

2 affected packages

dhcpcd, dhcpcd5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Not affected Not in release Not in release Not in release
dhcpcd5 Not in release Not affected Not affected Not affected
Show less packages

CVE-2014-6060

Medium priority

Some fixes available 1 of 4

The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers...

2 affected packages

dhcpcd, dhcpcd5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Not in release
dhcpcd5 Not affected
Show less packages

CVE-2013-2494

Low priority
Ignored

libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine...

2 affected packages

dhcp3, isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcp3
isc-dhcp
Show less packages