Isc dhcp server Relay-Forward Message Denial of Service Vulnerability
Release date:
Updated on:
Affected Systems:
Isc dhcp 4.0-4.2
Unaffected system:
Isc dhcp 4.2.0-P1
Isc dhcp 4.1.2
Isc dhcp 4.0.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 44615
Cve id: CVE-2010-3611
The Dynamic Host Configuration Protocol (DHCP) allows various devices on the IP network to obtain their own network configuration information, including IP addresses, subnet masks, and broadcast addresses.
If the DHCPv6 packet received by the server contains one or more Relay-Forward messages, and no message can provide the address in the link-address field, the server crashes when processing such packets.
<* Source: John Gibbins
Link: http://secunia.com/advisories/42082/
Http://www.isc.org/software/dhcp/advisories/cve-2010-3611
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ISC
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.isc.org/software/dhcp