CVE-2019-11766: Critical severity dhcpcd vulnerability
Published May 5, 2019
·Updated
dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6OPTIONPDEXCLUDE feature.
Affected Software
5 affected components
Dhcpcd Project Dhcpcd<6.11.7
Dhcpcd Project Dhcpcd>=7.0.0<7.2.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
May 5, 2019
CVE Published
via MITRE·05:18 AM
Data Sourced
via MITRE·05:18 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11766?
CVE-2019-11766 is classified as a medium-severity vulnerability due to its potential for exploiting buffer over-reads.
2
How do I fix CVE-2019-11766?
To fix CVE-2019-11766, users should upgrade to dhcpcd version 6.11.7 or 7.2.2 or later.
3
What systems are impacted by CVE-2019-11766?
CVE-2019-11766 affects dhcpcd versions before 6.11.7 and 7.x before 7.2.2, as well as specific versions of Debian Linux.
4
What is the nature of the vulnerability in CVE-2019-11766?
CVE-2019-11766 is a buffer over-read vulnerability that occurs in the D6_OPTION_PD_EXCLUDE feature of dhcpcd.
5
Who is responsible for addressing CVE-2019-11766?
The maintainers of the dhcpcd project and affected Linux distributions are responsible for addressing CVE-2019-11766 by providing patches.