UBUNTU-CVE-2018-5732
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-5732
UBUNTU-CVE-2018-5732
Summary:
Details: Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
References: https://ubuntu.com/security/CVE-2018-5732, https://kb.isc.org/article/AA-01565/75/CVE-2018-5732, https://ubuntu.com/security/notices/USN-3586-1, https://ubuntu.com/security/notices/USN-3586-2, https://www.cve.org/CVERecord?id=CVE-2018-5732
Affected packages
Package
Name: isc-dhcp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
