USN-3586-1
Dashboard / Vulnerabilities / USN-3586-1
USN-3586-1
Summary: isc-dhcp vulnerabilities
Details: Konstantin Orekhov discovered that the DHCP server incorrectly handled a large number of concurrent TCP sessions. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-2774) It was discovered that the DHCP server incorrectly handled socket descriptors. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2017-3144) Felix Wilhelm discovered that the DHCP client incorrectly handled certain malformed responses. A remote attacker could use this issue to cause the DHCP client to crash, resulting in a denial of service, or possibly execute arbitrary code. In the default installation, attackers would be isolated by the dhclient AppArmor profile. (CVE-2018-5732) Felix Wilhelm discovered that the DHCP server incorrectly handled reference counting. A remote attacker could possibly use this issue to cause the DHCP server to crash, resulting in a denial of service. (CVE-2018-5733)
References: https://ubuntu.com/security/notices/USN-3586-1, https://ubuntu.com/security/CVE-2016-2774, https://ubuntu.com/security/CVE-2017-3144, https://ubuntu.com/security/CVE-2018-5732, https://ubuntu.com/security/CVE-2018-5733
Affected packages
Package
Name: isc-dhcp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
