CVE-2011-2748: Input Validation
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet.
Other sources
Two flaws were found that could be used to cause the ISC DHCP server to halt when processing certain packets [1]. These could be used by an attacker to cause a denial of service for DHCP services.
These flaws are corrected in upstream versions 3.1-ESV-R3, 4.1-ESV-R3 and 4.2.2.
[1] http://www.isc.org/software/dhcp/advisories/cve-2011-2748
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2748?
CVE-2011-2748 is classified as a denial of service vulnerability affecting various versions of the ISC DHCP server.
How do I fix CVE-2011-2748?
To fix CVE-2011-2748, upgrade to ISC DHCP version 4.2.2 or later, or apply any relevant patches provided by your Linux distribution.
Which versions of ISC DHCP are affected by CVE-2011-2748?
CVE-2011-2748 affects ISC DHCP versions 3.x and 4.x prior to 4.2.2, including several specific ESV and RC versions.
Can CVE-2011-2748 be exploited remotely?
Yes, CVE-2011-2748 can be exploited remotely through specially crafted DHCP packets, potentially leading to server crashes.
What are the implications of CVE-2011-2748 for users?
The implications of CVE-2011-2748 for users include outages due to the DHCP server exiting unexpectedly, disrupting network services.