Skip to main content

ISC DHCP Denial of service Vulnerability

Last Update Date: 2 Apr 2013 15:00 Release Date: 2 Apr 2013 4821 Views

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability has been identified in ISC DHCP, which can be exploited by malicious user to to cause denial of service.

Exploitation of a memory exhaustion bug in libdns is theoretically possible in ISC DHCP 4.2, which uses the library from BIND 9 for Dynamic DNS.

 

Servers which are targeted by a successful attack will exhaust all memory available to the server process, which is likely to crash the DHCP server and may affect other processes running on the same physical machine when system memory is exhausted.


Impact

  • Denial of Service

System / Technologies affected

  • versions of DHCP 4.2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • upgrade to DHCP 4.2.5-P1

Vulnerability Identifier


Source


Related Link