CVE-2010-3611 – dhcp: NULL pointer dereference crash via crafted DHCPv6 packet
https://notcve.org/view.php?id=CVE-2010-3611
ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field. ISC DHCP server v4.0 anterior a v4.0.2, v4.1 anterior a v4.1.2, y v4.2 anterior a v4.2-P1 permite a atacantes remotos causar una denegación de servicio (caída) a través de un paquete DHCPv6 contiendo un mensaje Relay-Forward sin una dirección en el campo de dirección de enlace Relay-Forward • http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050766.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051287.html http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html http://osvdb.org/68999 http://secunia.com/advisories/42082 http://secunia.com/advisories/42345 http://secunia.com/advisories/42407 http://www.isc.org/software/dhcp/advisories/cve-2010-3611 http://www.kb.cert.org/vuls/id/102047 http://www.mandri • CWE-476: NULL Pointer Dereference •
CVE-2010-2156 – ISC DHCPD - Denial of Service
https://notcve.org/view.php?id=CVE-2010-2156
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID. ISC DHCP v4.1 anterior v4.1.1-P1 y v4.0 anterior v4.0.2-P1 permite a atacantes remotos causar una denegación de servicio (salida servidor) a través de un cliente ID zero-length. • https://www.exploit-db.com/exploits/14185 http://ftp.isc.org/isc/dhcp/dhcp-4.0.2-P1-RELNOTES http://ftp.isc.org/isc/dhcp/dhcp-4.1.1-P1-RELNOTES http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042843.html http://secunia.com/advisories/40116 http://www.exploit-db.com/exploits/14185 http://www.mandriva.com/security/advisories?name=MDVSA-2010:114 http://www.securityfocus.com/bid/40775 http://www.securitytracker.com/id?1024093 https://exchange.xfor • CWE-189: Numeric Errors •
CVE-2009-1893 – dhcp: insecure temporary file use in the dhcpd init script
https://notcve.org/view.php?id=CVE-2009-1893
The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command. La función configtest en la secuencia de comandos de inicio del DHCPD en Red Hat para DHCP 3.0.1 en Red Hat Enterprise Linux (RHEL) 3 permite a usuarios locales sobrescribir ficheros de su elección a través de un ataque de enlace simbólico sobre un fichero temporal no especificado, relativo al comando "dhcpd -t". • http://secunia.com/advisories/35831 http://securitytracker.com/id?1022554 http://www.redhat.com/support/errata/RHSA-2009-1154.html http://www.securityfocus.com/bid/35670 https://bugzilla.redhat.com/show_bug.cgi?id=510024 https://exchange.xforce.ibmcloud.com/vulnerabilities/51718 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11597 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6440 https://access.redhat.com/security • CWE-59: Improper Link Resolution Before File Access ('Link Following') CWE-377: Insecure Temporary File •
CVE-2009-1892
https://notcve.org/view.php?id=CVE-2009-1892
dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests. dhcpd en ISC DHCP v3.0.4 y v3.1.1, cuando se utilizan de forma simultánea el identificador de cliente dhcp y la configuración de hardware ethernet, permite a atacantes remotos provocar una denegación de servicio (caída del demonio) a través de una petición no especificada. • http://secunia.com/advisories/35830 http://secunia.com/advisories/35851 http://secunia.com/advisories/36457 http://secunia.com/advisories/37342 http://www.debian.org/security/2009/dsa-1833 http://www.mandriva.com/security/advisories?name=MDVSA-2009:154 http://www.securityfocus.com/bid/35669 https://exchange.xforce.ibmcloud.com/vulnerabilities/51717 https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01177.html https://www.redhat.com/archives/fedora-package-announce/200 • CWE-16: Configuration •
CVE-2009-0692 – ISC DHCP dhclient < 3.1.2p1 - Remote Buffer Overflow (PoC)
https://notcve.org/view.php?id=CVE-2009-0692
Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option. Desbordamiento de búfer basado en pila en el método script_write_params en client/dhclient.c en ISC DHCP dhclient v4.1 anteriores a v4.1.0p1, v4.0 anteriores a v4.0.1p1, v3.1 anteriores a v3.1.2p1, v3.0, y v2.0 permite a servidores DHCP remotos ejecutar código arbitrario a través de una opción manipulada subnet-mask. • https://www.exploit-db.com/exploits/9265 http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-010.txt.asc http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083 http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00003.html http://secunia.com/advisories/35785 http://secunia.com/advisories/35829 http://secunia.com/advisories/35830 http://secunia.com/advisories/35831 http://secunia.com/advisories/35832 http://secunia.com/advisories/35841 http • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-121: Stack-based Buffer Overflow •