CVE-2011-2749: Input Validation
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2749?
CVE-2011-2749 is categorized as a denial-of-service vulnerability that can cause the DHCP daemon to exit.
How do I fix CVE-2011-2749?
To fix CVE-2011-2749, upgrade to ISC DHCP version 4.2.2 or later, or apply patches provided by your OS vendor.
What systems are affected by CVE-2011-2749?
CVE-2011-2749 affects ISC DHCP versions 3.x and 4.x prior to 4.2.2 including several specific versions mentioned in the advisory.
Can CVE-2011-2749 be exploited remotely?
Yes, CVE-2011-2749 can be exploited remotely through a crafted BOOTP packet sent to the affected DHCP server.
What types of attacks can result from CVE-2011-2749?
Exploitation of CVE-2011-2749 can lead to service disruption by causing the DHCP daemon to crash, resulting in a denial of service.