CVE-2017-3144
Failure to properly clean up closed OMAPI connections can exhaust available sockets
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.
Una vulnerabilidad derivada del error al limpiar correctamente las conexiones OMAPI cerradas puede conducir al agotamiento del grupo de descriptores del socket disponibles para el servidor DHCP. Afecta a ISC DHCP desde la versión 4.1.0 hasta la 4.1-ESV-R15, desde la versión 4.2.0 hasta la 4.2.8 y desde la versión 4.3.0 hasta la 4.3.6. Las versiones anteriores podrían hacerse visto afectadas, pero han sobrepasado por mucho su fin de vida útil. Las versiones anteriores a la 4.1.0 no han sido probadas.
It was found that the DHCP daemon did not properly clean up closed OMAPI connections in certain cases. A remote attacker able to connect to the OMAPI port could use this flaw to exhaust file descriptors in the DHCP daemon, leading to a denial of service in the OMAPI functionality.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-02 CVE Reserved
- 2018-01-25 CVE Published
- 2024-02-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-772: Missing Release of Resource after Effective Lifetime
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102726 | Third Party Advisory | |
http://www.securitytracker.com/id/1040194 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:0158 | 2020-01-09 | |
https://kb.isc.org/docs/aa-01541 | 2020-01-09 | |
https://usn.ubuntu.com/3586-1 | 2020-01-09 | |
https://www.debian.org/security/2018/dsa-4133 | 2020-01-09 | |
https://access.redhat.com/security/cve/CVE-2017-3144 | 2018-01-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1522918 | 2018-01-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | >= 4.2.0 <= 4.2.8 Search vendor "Isc" for product "Dhcp" and version " >= 4.2.0 <= 4.2.8" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | >= 4.3.0 <= 4.3.6 Search vendor "Isc" for product "Dhcp" and version " >= 4.3.0 <= 4.3.6" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r10 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r10_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r10_rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11_rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11_rc2 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r12 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r12_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r12_p1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r13 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r13_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r14 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r14_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r15 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r2 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r3 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r3_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r4 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5_rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5_rc2 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r6 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r7 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r8 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r8_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r8_rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r9 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r9_b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r9_rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1.0 Search vendor "Isc" for product "Dhcp" and version "4.1.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 7.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "7.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 7.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "7.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 7.4 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "7.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 7.6 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "7.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.4 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.5 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.6 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 7.4 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "7.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 7.6 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "7.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 7.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "7.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 14.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 17.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "17.10" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|