6.5
CVE-2015-8605
- EPSS 76.45%
- Veröffentlicht 14.01.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sophos ≫ Unified Threat Management Up2date Version <= 9.318
Sophos ≫ Unified Threat Management Up2date Version <= 9.353
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 76.45% | 0.995 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5.7 | 5.5 | 6.9 |
AV:A/AC:M/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/
https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175594.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176031.html
http://lists.opensuse.org/opensuse-updates/2016-02/msg00162.html
http://lists.opensuse.org/opensuse-updates/2016-02/msg00168.html
http://www.debian.org/security/2016/dsa-3442
http://www.securityfocus.com/bid/80703
http://www.securitytracker.com/id/1034657
http://www.ubuntu.com/usn/USN-2868-1
https://kb.isc.org/article/AA-01334