CVE-2018-5732: A specially constructed response from a malicious server can cause a buffer overflow in dhclient
Failure to properly bounds check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section.
Versions of DHCP affected: 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
Other sources
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
— Launchpad
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5732?
The severity of CVE-2018-5732 is high with a CVSS score of 7.5.
How does CVE-2018-5732 affect ISC DHCP?
CVE-2018-5732 affects ISC DHCP versions 4.1.0 to 4.1.2, 4.2.0 to 4.2.8, and 4.3.0 to 4.3.6.
How does CVE-2018-5732 impact Ubuntu?
Ubuntu versions 12.04 LTS (Precise Pangolin), 14.04 LTS (Trusty Tahr), 16.04 LTS (Xenial Xerus), and 18.04 LTS (Bionic Beaver) are affected by CVE-2018-5732 in the ISC DHCP package.
How does CVE-2018-5732 impact Red Hat?
Red Hat is affected by CVE-2018-5732 in the dhcp package versions 4.1, 4.3.6, and 4.4.1.
What is the Common Weakness Enumeration (CWE) of CVE-2018-5732?
The CWE of CVE-2018-5732 is CWE-119, which refers to Improper Restriction of Operations within the Bounds of a Memory Buffer.