First published: Wed Jul 25 2012(Updated: )
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC DHCP | =4.1.0 | |
ISC DHCP | =4.1.0-a1 | |
ISC DHCP | =4.1.0-a2 | |
ISC DHCP | =4.1.0-b1 | |
ISC DHCP | =4.1.1 | |
ISC DHCP | =4.1.1-b1 | |
ISC DHCP | =4.1.1-b2 | |
ISC DHCP | =4.1.1-b3 | |
ISC DHCP | =4.1.1-rc1 | |
ISC DHCP | =4.1.2 | |
ISC DHCP | =4.1.2-b1 | |
ISC DHCP | =4.1.2-p1 | |
ISC DHCP | =4.1.2-rc1 | |
ISC DHCP | =4.2.0 | |
ISC DHCP | =4.2.0-a1 | |
ISC DHCP | =4.2.0-a2 | |
ISC DHCP | =4.2.0-b1 | |
ISC DHCP | =4.2.0-b2 | |
ISC DHCP | =4.2.0-p1 | |
ISC DHCP | =4.2.0-rc1 | |
ISC DHCP | =4.2.1 | |
ISC DHCP | =4.2.1-b1 | |
ISC DHCP | =4.2.1-rc1 | |
ISC DHCP | =4.2.2 | |
ISC DHCP | =4.2.2-b1 | |
ISC DHCP | =4.2.2-rc1 | |
ISC DHCP | =4.2.3 | |
ISC DHCP | =4.2.3-p1 | |
ISC DHCP | =4.2.3-p2 | |
ISC DHCP | =4.2.4 | |
ISC DHCP | =4.1-esv | |
ISC DHCP | =4.1-esv-r1 | |
ISC DHCP | =4.1-esv-r2 | |
ISC DHCP | =4.1-esv-r3 | |
ISC DHCP | =4.1-esv-r3_b1 | |
ISC DHCP | =4.1-esv-r4 | |
ISC DHCP | =4.1-esv-r5 | |
ISC DHCP | =4.1-esv-r5_b1 | |
ISC DHCP | =4.1-esv-r5_rc1 | |
ISC DHCP | =4.1-esv-r5_rc2 | |
ISC DHCP | =4.1-esv-rc1 | |
Debian Linux | =6.0 | |
Debian Linux | =7.0 | |
Ubuntu | =11.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3954 has been classified with a moderate severity due to its potential to cause denial of service through memory consumption.
To mitigate CVE-2012-3954, upgrade to ISC DHCP version 4.2.4-P1 or 4.1-ESV-R6 or later.
CVE-2012-3954 affects ISC DHCP versions 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6.
CVE-2012-3954 primarily leads to denial of service but may be part of a larger attack vector if exploited in conjunction with other vulnerabilities.
Attackers can exploit CVE-2012-3954 by sending numerous requests to the server, causing it to consume memory and potentially crash.