CVE-2010-2156: Medium severity ISC DHCP vulnerability
Published Jun 7, 2010
·Updated
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.
Affected Software
15 affected components
ISC DHCP=4.1.0
ISC DHCP=4.1.1-rc1
ISC DHCP=4.1.1-b2
ISC DHCP=4.1.1
ISC DHCP=4.1.1-b3
ISC DHCP=4.1.1-b1
ISC DHCP=4.0.2-b2
ISC DHCP=4.0.2-b3
ISC DHCP=4.0.2-b1
ISC DHCP=4.0.1
ISC DHCP=4.0.1-rc1
ISC DHCP=4.0.2
ISC DHCP=4.0.1-b1
ISC DHCP=4.0.2-rc1
ISC DHCP=4.0.0
Event History
Jun 7, 2010
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
Description
Data Sourced
via NVD·05:13 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2156?
CVE-2010-2156 has a severity rating that classifies it as a denial of service vulnerability.
2
How do I fix CVE-2010-2156?
To fix CVE-2010-2156, upgrade to ISC DHCP version 4.1.1-P1 or 4.0.2-P1 or later.
3
What causes the vulnerability described in CVE-2010-2156?
The vulnerability in CVE-2010-2156 is caused by the processing of a zero-length client ID which can lead to a server exit.
4
Which ISC DHCP versions are affected by CVE-2010-2156?
CVE-2010-2156 affects ISC DHCP versions 4.1.0, 4.1.1-rc1, 4.1.1-b2, 4.1.1, 4.0.2, 4.0.1, and other specific variants listed.
5
Can CVE-2010-2156 be exploited remotely?
Yes, CVE-2010-2156 can be exploited remotely by attackers sending crafted requests to the affected DHCP server.