First published: Mon Apr 11 2016(Updated: )
The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Debian Linux | =7.0 | |
dhcpcd | =3.1.9 | |
dhcpcd | =3.2.0 | |
dhcpcd | =3.2.1 | |
dhcpcd | =3.2.2 | |
dhcpcd | =3.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6700 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2012-6700, you should update dhcpcd to a version that has addressed the memory management issue.
CVE-2012-6700 affects dhcpcd versions 3.1.9, 3.2.0, 3.2.1, 3.2.2, and 3.2.3.
Yes, remote DHCP servers can exploit CVE-2012-6700 by sending a crafted response that triggers the denial of service.
The impact of CVE-2012-6700 on affected systems includes unexpected crashes and potential downtime due to denial of service.