CVE-2011-4868: Null Pointer Dereference
The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle the DHCPv6 lease structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets related to a lease-status update.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4868?
CVE-2011-4868 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2011-4868?
To fix CVE-2011-4868, upgrade to ISC DHCP version 4.2.3-P2 or later.
What types of attacks can exploit CVE-2011-4868?
CVE-2011-4868 can be exploited by remote attackers using crafted packets to trigger a NULL pointer dereference.
Which software versions are affected by CVE-2011-4868?
ISC DHCP versions prior to 4.2.3-P2, including versions 3.0 and various 3.0-beta2 versions, are affected.
What impact does CVE-2011-4868 have on network services?
CVE-2011-4868 can cause the ISC DHCP daemon to crash, leading to service disruptions in network environments.