CVE-2012-6698: Buffer Overflow
Published Apr 11, 2016
·Updated
The decodesearch function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.
Affected Software
6 affected components
Debian Debian Linux=7.0
Dhcpcd Project Dhcpcd=3.1.9
Dhcpcd Project Dhcpcd=3.2.0
Dhcpcd Project Dhcpcd=3.2.1
Dhcpcd Project Dhcpcd=3.2.2
Dhcpcd Project Dhcpcd=3.2.3
Event History
Apr 11, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6698?
CVE-2012-6698 is classified as a high-severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2012-6698?
To fix CVE-2012-6698, upgrade to dhcpcd version 3.2.4 or later.
3
Which versions of dhcpcd are affected by CVE-2012-6698?
CVE-2012-6698 affects dhcpcd versions 3.1.9, 3.2.0, 3.2.1, 3.2.2, and 3.2.3.
4
Can CVE-2012-6698 be exploited remotely?
Yes, CVE-2012-6698 can be exploited by remote DHCP servers through crafted responses.
5
What type of attack does CVE-2012-6698 facilitate?
CVE-2012-6698 facilitates an out-of-bounds write which can lead to a denial of service.