CVE-2013-2494: Buffer Overflow
Published Mar 28, 2013
·Updated
libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine running a dhcpd process, a related issue to CVE-2013-2266.
Affected Software
19 affected components
ISC DHCP=4.2.0
ISC DHCP=4.2.0-a1
ISC DHCP=4.2.0-a2
ISC DHCP=4.2.0-b1
ISC DHCP=4.2.0-b2
ISC DHCP=4.2.0-p1
ISC DHCP=4.2.0-rc1
ISC DHCP=4.2.1
ISC DHCP=4.2.1-b1
ISC DHCP=4.2.1-rc1
ISC DHCP=4.2.2
ISC DHCP=4.2.2-b1
ISC DHCP=4.2.2-rc1
ISC DHCP=4.2.3
ISC DHCP=4.2.3-p1
ISC DHCP=4.2.3-p2
ISC DHCP=4.2.4
ISC DHCP=4.2.4-p1
ISC DHCP=4.2.5
Event History
Mar 28, 2013
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2494?
CVE-2013-2494 is considered to have a high severity due to its potential to cause denial of service through memory exhaustion.
2
How do I fix CVE-2013-2494?
To fix CVE-2013-2494, upgrade ISC DHCP to version 4.2.5-P1 or later.
3
What software is affected by CVE-2013-2494?
CVE-2013-2494 affects ISC DHCP versions 4.2.0 through 4.2.4.
4
What kind of attack is associated with CVE-2013-2494?
CVE-2013-2494 is associated with a denial of service attack that can exploit regular expression processing.
5
Is there a patch available for CVE-2013-2494?
Yes, a patch is available by upgrading to ISC DHCP version 4.2.5-P1 or higher.