漏洞描述
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
redmine.pfsense.orghttp://redmine.pfsense.org/issues/1888↗bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=729382↗secunia.comhttp://secunia.com/advisories/45817↗www.mandriva.comhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:128↗kb.juniper.nethttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761↗security.gentoo.orghttp://security.gentoo.org/glsa/glsa-201301-06.xml↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-updates/2011-09/msg00014.html↗secunia.comhttp://secunia.com/advisories/46780↗secunia.comhttp://secunia.com/advisories/45918↗www.isc.orghttp://www.isc.org/software/dhcp/advisories/cve-2011-2748↗secunia.comhttp://secunia.com/advisories/45582↗secunia.comhttp://secunia.com/advisories/45595↗hermes.opensuse.orghttps://hermes.opensuse.org/messages/11695711↗bugzilla.redhat.comhttps://bugzilla.redhat.com/attachment.cgi?id=517665&action=diff↗www.securityfocus.comhttp://www.securityfocus.com/bid/49120↗secunia.comhttp://secunia.com/advisories/45639↗www.isc.orghttp://www.isc.org/files/release-notes/DHCP%204.2.2_0.html↗securitytracker.comhttp://securitytracker.com/id?1025918↗www.isc.orghttp://www.isc.org/files/release-notes/DHCP%203.1-ESV-R3_0.html↗www.ubuntu.comhttp://www.ubuntu.com/usn/USN-1190-1↗www.isc.orghttp://www.isc.org/files/release-notes/DHCP%204.1-ESV-R3.html↗exchange.xforce.ibmcloud.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/69139↗www.redhat.comhttp://www.redhat.com/support/errata/RHSA-2011-1160.html↗www.debian.orghttp://www.debian.org/security/2011/dsa-2292↗lists.fedoraproject.orghttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065176.html↗secunia.comhttp://secunia.com/advisories/45629↗