First published: Mon Jan 31 2011(Updated: )
The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) by sending a message over IPv6 for a declined and abandoned address.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC DHCP Server | =4.0 | |
ISC DHCP Server | =4.0.0 | |
ISC DHCP Server | =4.0.1 | |
ISC DHCP Server | =4.0.1-b1 | |
ISC DHCP Server | =4.0.1-rc1 | |
ISC DHCP Server | =4.0.2 | |
ISC DHCP Server | =4.0.2-b1 | |
ISC DHCP Server | =4.0.2-b2 | |
ISC DHCP Server | =4.0.2-b3 | |
ISC DHCP Server | =4.0.2-rc1 | |
ISC DHCP Server | =4.0.3 | |
ISC DHCP Server | =4.0.3-b1 | |
ISC DHCP Server | =4.0.3-rc1 | |
ISC DHCP Server | =4.1.0 | |
ISC DHCP Server | =4.1.1 | |
ISC DHCP Server | =4.1.1-b1 | |
ISC DHCP Server | =4.1.1-b2 | |
ISC DHCP Server | =4.1.1-b3 | |
ISC DHCP Server | =4.1.1-rc1 | |
ISC DHCP Server | =4.1.2 | |
ISC DHCP Server | =4.0-esv | |
ISC DHCP Server | =4.1-esv | |
ISC DHCP Server | =4.2.0 | |
ISC DHCP Server | =4.2.0-a1 | |
ISC DHCP Server | =4.2.0-a2 | |
ISC DHCP Server | =4.2.0-b1 | |
ISC DHCP Server | =4.2.0-b2 | |
ISC DHCP Server | =4.2.0-p1 | |
ISC DHCP Server | =4.2.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0413 is classified as a denial of service vulnerability due to potential assertion failure and daemon crashes.
To fix CVE-2011-0413, upgrade to ISC DHCP version 4.1.2-P1 or later for 4.1.x versions, or 4.2.1b1 or later for 4.2.x versions.
CVE-2011-0413 affects ISC DHCP versions 4.0.x, 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1.
Attackers can exploit CVE-2011-0413 to send specially crafted messages that result in denial of service to the DHCP daemon.
The best practice is to upgrade to the patched version, but temporarily limiting the exposure of the DHCP server may reduce risk.