6.5

CVE-2015-8605

ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Dhcp Version 4.0.0
Isc ≫ Dhcp Version 4.0.1
Isc ≫ Dhcp Version 4.0.2 Update -
Isc ≫ Dhcp Version 4.0.2 Update p1
Isc ≫ Dhcp Version 4.0.3 Update -
Isc ≫ Dhcp Version 4.0.3 Update rc1
Isc ≫ Dhcp Version 4.1-esv Update -
Isc ≫ Dhcp Version 4.1-esv Update r1
Isc ≫ Dhcp Version 4.1-esv Update r10
Isc ≫ Dhcp Version 4.1-esv Update r10_b1
Isc ≫ Dhcp Version 4.1-esv Update r11_b1
Isc ≫ Dhcp Version 4.1-esv Update r11_rc1
Isc ≫ Dhcp Version 4.1-esv Update r11_rc2
Isc ≫ Dhcp Version 4.1-esv Update r12
Isc ≫ Dhcp Version 4.1-esv Update r12_b1
Isc ≫ Dhcp Version 4.1-esv Update r2
Isc ≫ Dhcp Version 4.1-esv Update r3
Isc ≫ Dhcp Version 4.1-esv Update r3_b1
Isc ≫ Dhcp Version 4.1-esv Update r4
Isc ≫ Dhcp Version 4.1-esv Update r5
Isc ≫ Dhcp Version 4.1-esv Update r5_b1
Isc ≫ Dhcp Version 4.1-esv Update r5_rc1
Isc ≫ Dhcp Version 4.1-esv Update r5_rc2
Isc ≫ Dhcp Version 4.1-esv Update r6
Isc ≫ Dhcp Version 4.1-esv Update r7
Isc ≫ Dhcp Version 4.1-esv Update r8
Isc ≫ Dhcp Version 4.1-esv Update r8_b1
Isc ≫ Dhcp Version 4.1-esv Update r8_rc1
Isc ≫ Dhcp Version 4.1-esv Update r9
Isc ≫ Dhcp Version 4.1-esv Update r9_b1
Isc ≫ Dhcp Version 4.1-esv Update r9_rc1
Isc ≫ Dhcp Version 4.1.0 Update -
Isc ≫ Dhcp Version 4.1.1 Update -
Isc ≫ Dhcp Version 4.1.1 Update p1
Isc ≫ Dhcp Version 4.1.2 Update -
Isc ≫ Dhcp Version 4.1.2 Update b1
Isc ≫ Dhcp Version 4.1.2 Update p1
Isc ≫ Dhcp Version 4.1.2 Update rc1
Isc ≫ Dhcp Version 4.2.0 Update -
Isc ≫ Dhcp Version 4.2.0 Update p1
Isc ≫ Dhcp Version 4.2.0 Update p2
Isc ≫ Dhcp Version 4.2.1 Update -
Isc ≫ Dhcp Version 4.2.1 Update b1
Isc ≫ Dhcp Version 4.2.1 Update p1
Isc ≫ Dhcp Version 4.2.1 Update rc1
Isc ≫ Dhcp Version 4.2.2 Update -
Isc ≫ Dhcp Version 4.2.2 Update b1
Isc ≫ Dhcp Version 4.2.2 Update rc1
Isc ≫ Dhcp Version 4.2.3 Update -
Isc ≫ Dhcp Version 4.2.3 Update p1
Isc ≫ Dhcp Version 4.2.3 Update p2
Isc ≫ Dhcp Version 4.2.4 Update -
Isc ≫ Dhcp Version 4.2.4 Update b1
Isc ≫ Dhcp Version 4.2.4 Update p1
Isc ≫ Dhcp Version 4.2.4 Update p2
Isc ≫ Dhcp Version 4.2.4 Update rc1
Isc ≫ Dhcp Version 4.2.4 Update rc2
Isc ≫ Dhcp Version 4.2.5 Update -
Isc ≫ Dhcp Version 4.2.5 Update b1
Isc ≫ Dhcp Version 4.2.5 Update p1
Isc ≫ Dhcp Version 4.2.5 Update rc1
Isc ≫ Dhcp Version 4.2.6 Update -
Isc ≫ Dhcp Version 4.2.6 Update b1
Isc ≫ Dhcp Version 4.2.6 Update rc1
Isc ≫ Dhcp Version 4.2.7
Isc ≫ Dhcp Version 4.2.7 Update b1
Isc ≫ Dhcp Version 4.2.7 Update rc1
Isc ≫ Dhcp Version 4.2.8
Isc ≫ Dhcp Version 4.2.8 Update b1
Isc ≫ Dhcp Version 4.2.8 Update rc1
Isc ≫ Dhcp Version 4.2.8 Update rc2
Isc ≫ Dhcp Version 4.3.0
Isc ≫ Dhcp Version 4.3.0 Update a1
Isc ≫ Dhcp Version 4.3.0 Update b1
Isc ≫ Dhcp Version 4.3.0 Update rc1
Isc ≫ Dhcp Version 4.3.1
Isc ≫ Dhcp Version 4.3.1 Update b1
Isc ≫ Dhcp Version 4.3.1 Update rc1
Isc ≫ Dhcp Version 4.3.2
Isc ≫ Dhcp Version 4.3.2 Update b1
Isc ≫ Dhcp Version 4.3.2 Update rc1
Isc ≫ Dhcp Version 4.3.2 Update rc2
Isc ≫ Dhcp Version 4.3.3
Isc ≫ Dhcp Version 4.3.3 Update b1
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 76.45% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5.7 5.5 6.9
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
Third Party Advisory
https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/
Third Party Advisory
https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175594.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176031.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2016-02/msg00162.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-updates/2016-02/msg00168.html
Third Party Advisory
Mailing List
http://www.debian.org/security/2016/dsa-3442
Third Party Advisory
http://www.securityfocus.com/bid/80703
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034657
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-2868-1
Third Party Advisory
https://kb.isc.org/article/AA-01334
Vendor Advisory