// For flags

CVE-2018-5732

A specially constructed response from a malicious server can cause a buffer overflow in dhclient

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0

Un fallo al comprobar apropiadamente los límites de un búfer usado para procesar las opciones de DHCP, permite a un servidor malicioso (o a una entidad que se hace pasar por un servidor) causar un desbordamiento del búfer (y el bloqueo resultante) en dhclient mediante el envío de una respuesta que contiene una sección de opciones especialmente construida. Afecta a ISC DHCP versiones 4.1.0 hasta 4.1-ESV-R15, 4.2.0 hasta 4.2.8, 4.3.0 hasta 4.3.6, y 4.4.0.

An out-of-bound memory access flaw was found in the way dhclient processed a DHCP response packet. A malicious DHCP server could potentially use this flaw to crash dhclient processes running on DHCP client machines via a crafted DHCP response packet.

*Credits: ISC would like to thank Felix Wilhelm, Google Security Team, for reporting this vulnerability.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-17 CVE Reserved
  • 2018-03-01 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
>= 4.1.0 <= 4.1.2
Search vendor "Isc" for product "Dhcp" and version " >= 4.1.0 <= 4.1.2"
-
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
>= 4.2.0 < 4.2.8
Search vendor "Isc" for product "Dhcp" and version " >= 4.2.0 < 4.2.8"
-
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
>= 4.3.0 < 4.3.6
Search vendor "Isc" for product "Dhcp" and version " >= 4.3.0 < 4.3.6"
-
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
-
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r10
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r10b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r10rc1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r11
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r11b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r11rc1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r11rc2
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r12
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r12-p1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r12b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r13
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r13b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r14
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r14b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r15
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r2
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r3
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r3b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r4
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r5
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r5b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r5rc1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r5rc2
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r6
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r7
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r8
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r8b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r8rc1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r9
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r9b1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1-esv
Search vendor "Isc" for product "Dhcp" and version "4.1-esv"
r9rc1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.1.2
Search vendor "Isc" for product "Dhcp" and version "4.1.2"
p1
Affected
Isc
Search vendor "Isc"
Dhcp
Search vendor "Isc" for product "Dhcp"
4.4.0
Search vendor "Isc" for product "Dhcp" and version "4.4.0"
-
Affected