CVE-2018-5733: A malicious client can overflow a reference counter in ISC dhcpd
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash.
Versions of DHCP affected: 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
Other sources
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0.
— Launchpad
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5733?
CVE-2018-5733 is considered a high severity vulnerability as it can lead to the crash of a DHCP server.
How do I fix CVE-2018-5733?
To fix CVE-2018-5733, upgrade the DHCP server software to versions 4.1.1 or later, or apply the necessary patches provided by your distribution.
What software is affected by CVE-2018-5733?
CVE-2018-5733 affects ISC DHCP versions 4.1.0 through 4.2.8 as well as specific versions up to 4.3.6 and 4.4.1.
What could an attacker do with CVE-2018-5733?
An attacker could exploit CVE-2018-5733 by sending a large volume of traffic to overwhelm the DHCP server, potentially leading to service disruptions.
Is CVE-2018-5733 a remote code execution vulnerability?
No, CVE-2018-5733 does not involve remote code execution; it can cause a denial of service by crashing the DHCP service instead.