CVE-2018-5732
A specially constructed response from a malicious server can cause a buffer overflow in dhclient
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
Un fallo al comprobar apropiadamente los límites de un búfer usado para procesar las opciones de DHCP, permite a un servidor malicioso (o a una entidad que se hace pasar por un servidor) causar un desbordamiento del búfer (y el bloqueo resultante) en dhclient mediante el envío de una respuesta que contiene una sección de opciones especialmente construida. Afecta a ISC DHCP versiones 4.1.0 hasta 4.1-ESV-R15, 4.2.0 hasta 4.2.8, 4.3.0 hasta 4.3.6, y 4.4.0.
An out-of-bound memory access flaw was found in the way dhclient processed a DHCP response packet. A malicious DHCP server could potentially use this flaw to crash dhclient processes running on DHCP client machines via a crafted DHCP response packet.
USN-3586-1 fixed a vulnerability in DHCP. This update provides the corresponding update for Ubuntu 12.04 ESM. Felix Wilhelm discovered that the DHCP client incorrectly handled certain malformed responses. A remote attacker could use this issue to cause the DHCP client to crash, resulting in a denial of service, or possibly execute arbitrary code. In the default installation, attackers would be isolated by the dhclient AppArmor profile. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-17 CVE Reserved
- 2018-03-01 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://kb.isc.org/docs/aa-01565 | 2020-01-09 | |
https://access.redhat.com/security/cve/CVE-2018-5732 | 2018-03-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1549960 | 2018-03-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | >= 4.1.0 <= 4.1.2 Search vendor "Isc" for product "Dhcp" and version " >= 4.1.0 <= 4.1.2" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | >= 4.2.0 < 4.2.8 Search vendor "Isc" for product "Dhcp" and version " >= 4.2.0 < 4.2.8" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | >= 4.3.0 < 4.3.6 Search vendor "Isc" for product "Dhcp" and version " >= 4.3.0 < 4.3.6" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r10 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r10b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r10rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r11rc2 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r12 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r12-p1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r12b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r13 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r13b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r14 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r14b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r15 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r2 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r3 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r3b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r4 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r5rc2 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r6 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r7 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r8 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r8b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r8rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r9 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r9b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1-esv Search vendor "Isc" for product "Dhcp" and version "4.1-esv" | r9rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1.2 Search vendor "Isc" for product "Dhcp" and version "4.1.2" | p1 |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.4.0 Search vendor "Isc" for product "Dhcp" and version "4.4.0" | - |
Affected
|