CVE-2011-0413: Input Validation
The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) by sending a message over IPv6 for a declined and abandoned address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0413?
CVE-2011-0413 is classified as a denial of service vulnerability due to potential assertion failure and daemon crashes.
How do I fix CVE-2011-0413?
To fix CVE-2011-0413, upgrade to ISC DHCP version 4.1.2-P1 or later for 4.1.x versions, or 4.2.1b1 or later for 4.2.x versions.
Which ISC DHCP versions are affected by CVE-2011-0413?
CVE-2011-0413 affects ISC DHCP versions 4.0.x, 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1.
What can attackers do with CVE-2011-0413?
Attackers can exploit CVE-2011-0413 to send specially crafted messages that result in denial of service to the DHCP daemon.
Is there a workaround for CVE-2011-0413?
The best practice is to upgrade to the patched version, but temporarily limiting the exposure of the DHCP server may reduce risk.