First published: Thu Mar 28 2013(Updated: )
libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine running a dhcpd process, a related issue to CVE-2013-2266.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC DHCP Server | =4.2.0 | |
ISC DHCP Server | =4.2.0-a1 | |
ISC DHCP Server | =4.2.0-a2 | |
ISC DHCP Server | =4.2.0-b1 | |
ISC DHCP Server | =4.2.0-b2 | |
ISC DHCP Server | =4.2.0-p1 | |
ISC DHCP Server | =4.2.0-rc1 | |
ISC DHCP Server | =4.2.1 | |
ISC DHCP Server | =4.2.1-b1 | |
ISC DHCP Server | =4.2.1-rc1 | |
ISC DHCP Server | =4.2.2 | |
ISC DHCP Server | =4.2.2-b1 | |
ISC DHCP Server | =4.2.2-rc1 | |
ISC DHCP Server | =4.2.3 | |
ISC DHCP Server | =4.2.3-p1 | |
ISC DHCP Server | =4.2.3-p2 | |
ISC DHCP Server | =4.2.4 | |
ISC DHCP Server | =4.2.4-p1 | |
ISC DHCP Server | =4.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2494 is considered to have a high severity due to its potential to cause denial of service through memory exhaustion.
To fix CVE-2013-2494, upgrade ISC DHCP to version 4.2.5-P1 or later.
CVE-2013-2494 affects ISC DHCP versions 4.2.0 through 4.2.4.
CVE-2013-2494 is associated with a denial of service attack that can exploit regular expression processing.
Yes, a patch is available by upgrading to ISC DHCP version 4.2.5-P1 or higher.