7.1

CVE-2016-2774

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Dhcp Version 4.1-esv Update -
Isc ≫ Dhcp Version 4.1-esv Update r1
Isc ≫ Dhcp Version 4.1-esv Update r10
Isc ≫ Dhcp Version 4.1-esv Update r10_b1
Isc ≫ Dhcp Version 4.1-esv Update r11_b1
Isc ≫ Dhcp Version 4.1-esv Update r11_rc1
Isc ≫ Dhcp Version 4.1-esv Update r11_rc2
Isc ≫ Dhcp Version 4.1-esv Update r12
Isc ≫ Dhcp Version 4.1-esv Update r12_b1
Isc ≫ Dhcp Version 4.1-esv Update r2
Isc ≫ Dhcp Version 4.1-esv Update r3
Isc ≫ Dhcp Version 4.1-esv Update r3_b1
Isc ≫ Dhcp Version 4.1-esv Update r4
Isc ≫ Dhcp Version 4.1-esv Update r5
Isc ≫ Dhcp Version 4.1-esv Update r5_b1
Isc ≫ Dhcp Version 4.1-esv Update r5_rc1
Isc ≫ Dhcp Version 4.1-esv Update r5_rc2
Isc ≫ Dhcp Version 4.1-esv Update r6
Isc ≫ Dhcp Version 4.1-esv Update r7
Isc ≫ Dhcp Version 4.1-esv Update r8
Isc ≫ Dhcp Version 4.1-esv Update r8_b1
Isc ≫ Dhcp Version 4.1-esv Update r8_rc1
Isc ≫ Dhcp Version 4.1-esv Update r9
Isc ≫ Dhcp Version 4.1-esv Update r9_b1
Isc ≫ Dhcp Version 4.1-esv Update r9_rc1
Isc ≫ Dhcp Version 4.1-esv Update rc1
Isc ≫ Dhcp Version 4.1.0 Update -
Isc ≫ Dhcp Version 4.1.0 Update a1
Isc ≫ Dhcp Version 4.1.0 Update a2
Isc ≫ Dhcp Version 4.1.0 Update b1
Isc ≫ Dhcp Version 4.1.1 Update -
Isc ≫ Dhcp Version 4.1.1 Update b1
Isc ≫ Dhcp Version 4.1.1 Update b2
Isc ≫ Dhcp Version 4.1.1 Update b3
Isc ≫ Dhcp Version 4.1.1 Update p1
Isc ≫ Dhcp Version 4.1.1 Update rc1
Isc ≫ Dhcp Version 4.1.2 Update -
Isc ≫ Dhcp Version 4.1.2 Update b1
Isc ≫ Dhcp Version 4.1.2 Update p1
Isc ≫ Dhcp Version 4.1.2 Update rc1
Isc ≫ Dhcp Version 4.2.0 Update -
Isc ≫ Dhcp Version 4.2.0 Update a1
Isc ≫ Dhcp Version 4.2.0 Update a2
Isc ≫ Dhcp Version 4.2.0 Update b1
Isc ≫ Dhcp Version 4.2.0 Update b2
Isc ≫ Dhcp Version 4.2.0 Update p1
Isc ≫ Dhcp Version 4.2.0 Update p2
Isc ≫ Dhcp Version 4.2.0 Update rc1
Isc ≫ Dhcp Version 4.2.1 Update -
Isc ≫ Dhcp Version 4.2.1 Update b1
Isc ≫ Dhcp Version 4.2.1 Update p1
Isc ≫ Dhcp Version 4.2.1 Update rc1
Isc ≫ Dhcp Version 4.2.2 Update -
Isc ≫ Dhcp Version 4.2.2 Update b1
Isc ≫ Dhcp Version 4.2.2 Update rc1
Isc ≫ Dhcp Version 4.2.3 Update -
Isc ≫ Dhcp Version 4.2.3 Update p1
Isc ≫ Dhcp Version 4.2.3 Update p2
Isc ≫ Dhcp Version 4.2.4 Update -
Isc ≫ Dhcp Version 4.2.4 Update b1
Isc ≫ Dhcp Version 4.2.4 Update p1
Isc ≫ Dhcp Version 4.2.4 Update p2
Isc ≫ Dhcp Version 4.2.4 Update rc1
Isc ≫ Dhcp Version 4.2.4 Update rc2
Isc ≫ Dhcp Version 4.2.5 Update -
Isc ≫ Dhcp Version 4.2.5 Update b1
Isc ≫ Dhcp Version 4.2.5 Update p1
Isc ≫ Dhcp Version 4.2.5 Update rc1
Isc ≫ Dhcp Version 4.2.6 Update -
Isc ≫ Dhcp Version 4.2.6 Update b1
Isc ≫ Dhcp Version 4.2.6 Update rc1
Isc ≫ Dhcp Version 4.2.7 Update -
Isc ≫ Dhcp Version 4.2.7 Update b1
Isc ≫ Dhcp Version 4.2.7 Update rc1
Isc ≫ Dhcp Version 4.2.8 Update -
Isc ≫ Dhcp Version 4.2.8 Update b1
Isc ≫ Dhcp Version 4.2.8 Update rc1
Isc ≫ Dhcp Version 4.2.8 Update rc2
Isc ≫ Dhcp Version 4.3.0 Update -
Isc ≫ Dhcp Version 4.3.0 Update a1
Isc ≫ Dhcp Version 4.3.0 Update b1
Isc ≫ Dhcp Version 4.3.0 Update rc1
Isc ≫ Dhcp Version 4.3.1 Update -
Isc ≫ Dhcp Version 4.3.1 Update b1
Isc ≫ Dhcp Version 4.3.1 Update rc1
Isc ≫ Dhcp Version 4.3.2 Update -
Isc ≫ Dhcp Version 4.3.2 Update b1
Isc ≫ Dhcp Version 4.3.2 Update rc1
Isc ≫ Dhcp Version 4.3.2 Update rc2
Isc ≫ Dhcp Version 4.3.3 Update -
Isc ≫ Dhcp Version 4.3.3 Update b1
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 73.62% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183458.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183640.html
Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2016-07/msg00066.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2016-2590.html
Third Party Advisory
http://www.securityfocus.com/bid/84208
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1035196
Third Party Advisory
VDB Entry
https://kb.isc.org/article/AA-01354
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/11/msg00023.html
Third Party Advisory
https://usn.ubuntu.com/3586-1/
Third Party Advisory