CVE-2019-6473: A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate
Published Oct 16, 2019
·Updated
An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
Affected Software
3 affected components
Ics Kea>=1.4.0<=1.5.0
Ics Kea=1.6.0-beta1
Ics Kea=1.6.0-beta2
Remediation
Information
Upgrade to a version of Kea containing a fix, available via
https://www.isc.org/downloads.
- Kea 1.4.0-P2
- Kea 1.5.0-P1
- Kea 1.6.0
Event History
Oct 16, 2019
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What version of ISC Kea is affected by CVE-2019-6473?
CVE-2019-6473 affects ISC Kea versions 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
2
What is the severity of CVE-2019-6473?
CVE-2019-6473 is rated as a moderate severity vulnerability due to its impact on service availability.
3
How do I fix CVE-2019-6473?
To fix CVE-2019-6473, upgrade to a version of ISC Kea that is not affected, such as 1.5.1 or later.
4
What type of issue is described by CVE-2019-6473?
CVE-2019-6473 describes an assertion failure caused by an invalid hostname option in the Kea DHCPv4 server.
5
What happens if I leave CVE-2019-6473 unaddressed?
If CVE-2019-6473 is left unaddressed, the Kea DHCP server may crash when receiving a malformed hostname option, resulting in service downtime.