5

CVE-2011-4539

dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Dhcp Version 4.0
Isc ≫ Dhcp Version 4.0.0
Isc ≫ Dhcp Version 4.0.1 Update -
Isc ≫ Dhcp Version 4.0.1 Update b1
Isc ≫ Dhcp Version 4.0.1 Update rc1
Isc ≫ Dhcp Version 4.0.2 Update -
Isc ≫ Dhcp Version 4.0.2 Update b1
Isc ≫ Dhcp Version 4.0.2 Update b2
Isc ≫ Dhcp Version 4.0.2 Update b3
Isc ≫ Dhcp Version 4.0.2 Update rc1
Isc ≫ Dhcp Version 4.0.3 Update -
Isc ≫ Dhcp Version 4.0.3 Update b1
Isc ≫ Dhcp Version 4.0.3 Update rc1
Isc ≫ Dhcp Version 4.1.1 Update b3
Isc ≫ Dhcp Version 4.1.1 Update rc1
Isc ≫ Dhcp Version 4.1.2
Isc ≫ Dhcp Version 4.2.0 Update -
Isc ≫ Dhcp Version 4.2.0 Update a1
Isc ≫ Dhcp Version 4.2.0 Update a2
Isc ≫ Dhcp Version 4.2.0 Update b1
Isc ≫ Dhcp Version 4.2.0 Update b2
Isc ≫ Dhcp Version 4.2.0 Update p1
Isc ≫ Dhcp Version 4.2.0 Update rc1
Isc ≫ Dhcp Version 4.2.1 Update -
Isc ≫ Dhcp Version 4.2.1 Update b1
Isc ≫ Dhcp Version 4.2.1 Update rc1
Isc ≫ Dhcp Version 4.2.2 Update -
Isc ≫ Dhcp Version 4.2.2 Update b1
Isc ≫ Dhcp Version 4.2.2 Update rc1
Isc ≫ Dhcp Version 4.2.3 Update -
Isc ≫ Dhcp Version 4.1-esv Update -
Isc ≫ Dhcp Version 4.1-esv Update r1
Isc ≫ Dhcp Version 4.1-esv Update r2
Isc ≫ Dhcp Version 4.1-esv Update r3
Isc ≫ Dhcp Version 4.1-esv Update r3_b1
Canonical ≫ Ubuntu Linux Version 11.04
Canonical ≫ Ubuntu Linux Version 11.10
Debian ≫ Debian Linux Version 6.0
Debian ≫ Debian Linux Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.22% 0.964
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://security.gentoo.org/glsa/glsa-201301-06.xml
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070980.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071549.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2011-12/msg00006.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/47153
Third Party Advisory
http://secunia.com/advisories/47178
Third Party Advisory
http://www.debian.org/security/2012/dsa-2519
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:182
Third Party Advisory
http://www.securityfocus.com/bid/50971
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1026393
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-1309-1
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/71680
Third Party Advisory
VDB Entry
https://www.isc.org/software/dhcp/advisories/cve-2011-4539
Vendor Advisory