CVE-2010-3616: Input Validation
ISC DHCP server 4.2 before 4.2.0-P2, when configured to use failover partnerships, allows remote attackers to cause a denial of service (communications-interrupted state and DHCP client service loss) by connecting to a port that is only intended for a failover peer, as demonstrated by a Nagios checktcp process check to TCP port 520.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3616?
CVE-2010-3616 has a severity rating that indicates a denial of service vulnerability in ISC DHCP server 4.2.
How do I fix CVE-2010-3616?
To fix CVE-2010-3616, update ISC DHCP server to version 4.2.0-P2 or later.
What causes the vulnerability in CVE-2010-3616?
CVE-2010-3616 is caused by remote attackers sending requests to a port designated for failover peers, disrupting DHCP services.
Which software is affected by CVE-2010-3616?
CVE-2010-3616 affects ISC DHCP server versions 4.2.0 and 4.2.0-P1.
Is CVE-2010-3616 an exploitable vulnerability?
Yes, CVE-2010-3616 can be exploited to cause a denial of service by interrupting communications for DHCP clients.