CVE-2011-4539

ISC DHCP 4.x < 4.2.3-P1 and 4.1-ESV < 4.1-ESV-R4 - Denial of Service via Crafted Request Packet

Title source: llm
STIX 2.1

Description

dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.

References (13)

Core 13
Core References
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:182
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47153
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071549.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1309-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2011-12/msg00006.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71680
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47178
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070980.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2519
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026393
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201301-06.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50971

Scores

EPSS 0.3226
EPSS Percentile 96.9%

Details

CWE
CWE-20
Status published
Products (16)
canonical/ubuntu_linux 11.04
canonical/ubuntu_linux 11.10
debian/debian_linux 6.0
debian/debian_linux 7.0
isc/dhcp 4.0
isc/dhcp 4.0.0
isc/dhcp 4.0.1 (3 CPE variants)
isc/dhcp 4.0.2 (5 CPE variants)
isc/dhcp 4.0.3 (3 CPE variants)
isc/dhcp 4.1.1 b3 (2 CPE variants)
... and 6 more
Published Dec 08, 2011
Tracked Since Feb 18, 2026