CVE-2012-6699: Buffer Overflow
Published Apr 11, 2016
·Updated
The decodesearch function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.
Affected Software
6 affected components
Debian Debian Linux=7.0
Dhcpcd Project Dhcpcd=3.1.9
Dhcpcd Project Dhcpcd=3.2.0
Dhcpcd Project Dhcpcd=3.2.1
Dhcpcd Project Dhcpcd=3.2.2
Dhcpcd Project Dhcpcd=3.2.3
Event History
Apr 11, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6699?
CVE-2012-6699 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2012-6699?
To fix CVE-2012-6699, you should update to a patched version of dhcpcd that addresses the out-of-bounds read issue.
3
Which versions are affected by CVE-2012-6699?
CVE-2012-6699 affects dhcpcd versions 3.1.9, 3.2.0, 3.2.1, 3.2.2, and 3.2.3 on Debian 7.0.
4
What systems are vulnerable to CVE-2012-6699?
Systems running Debian GNU/Linux 7.0 with vulnerable versions of dhcpcd are at risk from CVE-2012-6699.
5
Is there a known exploit for CVE-2012-6699?
Yes, CVE-2012-6699 can be exploited by remote DHCP servers to cause denial of service through crafted responses.