CVE-2012-3570: Buffer Overflow
Published Jul 25, 2012
·Updated
Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fault and daemon exit) via a crafted client identifier parameter.
Affected Software
17 affected components
ISC DHCP=4.2.0
ISC DHCP=4.2.0-a1
ISC DHCP=4.2.0-a2
ISC DHCP=4.2.0-b1
ISC DHCP=4.2.0-b2
ISC DHCP=4.2.0-p1
ISC DHCP=4.2.0-rc1
ISC DHCP=4.2.1
ISC DHCP=4.2.1-b1
ISC DHCP=4.2.1-rc1
ISC DHCP=4.2.2
ISC DHCP=4.2.2-b1
ISC DHCP=4.2.2-rc1
ISC DHCP=4.2.3
ISC DHCP=4.2.3-p1
ISC DHCP=4.2.3-p2
ISC DHCP=4.2.4
Event History
Jul 25, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3570?
CVE-2012-3570 is considered a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2012-3570?
To mitigate CVE-2012-3570, upgrade ISC DHCP to version 4.2.4-P1 or later.
3
What causes the CVE-2012-3570 vulnerability?
CVE-2012-3570 is caused by a buffer overflow when DHCPv6 mode is enabled.
4
Which software versions are affected by CVE-2012-3570?
CVE-2012-3570 affects ISC DHCP versions 4.2.0 through 4.2.3 inclusive.
5
What are the consequences of exploiting CVE-2012-3570?
Exploitation of CVE-2012-3570 can lead to a segmentation fault and result in the DHCP daemon exiting.