CVE-2009-1892: Medium severity ISC DHCP vulnerability
dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1892?
CVE-2009-1892 is classified as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2009-1892?
To mitigate CVE-2009-1892, upgrade to a patched version of ISC DHCP that is not affected, ideally version 3.1.2 or later.
What systems are vulnerable to CVE-2009-1892?
CVE-2009-1892 affects ISC DHCP versions 3.0.4, 3.0.4_b1, 3.0.4_b2, 3.0.4_b3, and 3.1.1.
What type of attack does CVE-2009-1892 exploit?
CVE-2009-1892 can be exploited through malformed requests that affect the dhcpd daemon, causing it to crash.
Is CVE-2009-1892 still an issue today?
CVE-2009-1892 is considered obsolete as long as affected systems have been updated to a secure version.