CVE-2020-7217: High severity openSUSE wicked vulnerability
Published Feb 10, 2020
·Updated
An nidhcp4fsmprocessdhcp4packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.
Affected Software
1 affected component
openSUSE wicked<=0.6.55
Event History
Feb 10, 2020
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
Description
Feb 11, 2020
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7217?
CVE-2020-7217 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-7217?
To mitigate CVE-2020-7217, upgrade to openSUSE wicked version 0.6.56 or later.
3
What causes CVE-2020-7217 in openSUSE wicked?
CVE-2020-7217 is caused by a memory leak in the ni_dhcp4_fsm_process_dhcp4_packet function when processing malformed DHCP4 packets.
4
Who is affected by CVE-2020-7217?
Users of openSUSE wicked versions 0.6.55 and earlier are affected by CVE-2020-7217.
5
What type of attack does CVE-2020-7217 enable?
CVE-2020-7217 allows network attackers to perform a denial of service through crafted DHCP4 packets.