First published: Thu Mar 01 2018(Updated: )
Konstantin Orekhov discovered that the DHCP server incorrectly handled a large number of concurrent TCP sessions. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-2774) It was discovered that the DHCP server incorrectly handled socket descriptors. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2017-3144) Felix Wilhelm discovered that the DHCP client incorrectly handled certain malformed responses. A remote attacker could use this issue to cause the DHCP client to crash, resulting in a denial of service, or possibly execute arbitrary code. In the default installation, attackers would be isolated by the dhclient AppArmor profile. (CVE-2018-5732) Felix Wilhelm discovered that the DHCP server incorrectly handled reference counting. A remote attacker could possibly use this issue to cause the DHCP server to crash, resulting in a denial of service. (CVE-2018-5733)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/isc-dhcp-client | <4.3.5-3ubuntu2.2 | 4.3.5-3ubuntu2.2 |
=17.10 | ||
All of | ||
ubuntu/isc-dhcp-relay | <4.3.5-3ubuntu2.2 | 4.3.5-3ubuntu2.2 |
=17.10 | ||
All of | ||
ubuntu/isc-dhcp-server | <4.3.5-3ubuntu2.2 | 4.3.5-3ubuntu2.2 |
=17.10 | ||
All of | ||
ubuntu/isc-dhcp-server-ldap | <4.3.5-3ubuntu2.2 | 4.3.5-3ubuntu2.2 |
=17.10 | ||
All of | ||
ubuntu/isc-dhcp-client | <4.3.3-5ubuntu12.9 | 4.3.3-5ubuntu12.9 |
=16.04 | ||
All of | ||
ubuntu/isc-dhcp-relay | <4.3.3-5ubuntu12.9 | 4.3.3-5ubuntu12.9 |
=16.04 | ||
All of | ||
ubuntu/isc-dhcp-server | <4.3.3-5ubuntu12.9 | 4.3.3-5ubuntu12.9 |
=16.04 | ||
All of | ||
ubuntu/isc-dhcp-server-ldap | <4.3.3-5ubuntu12.9 | 4.3.3-5ubuntu12.9 |
=16.04 | ||
All of | ||
ubuntu/isc-dhcp-client | <4.2.4-7ubuntu12.12 | 4.2.4-7ubuntu12.12 |
=14.04 | ||
All of | ||
ubuntu/isc-dhcp-relay | <4.2.4-7ubuntu12.12 | 4.2.4-7ubuntu12.12 |
=14.04 | ||
All of | ||
ubuntu/isc-dhcp-server | <4.2.4-7ubuntu12.12 | 4.2.4-7ubuntu12.12 |
=14.04 | ||
All of | ||
ubuntu/isc-dhcp-server-ldap | <4.2.4-7ubuntu12.12 | 4.2.4-7ubuntu12.12 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-3586-1 is medium.
The DHCP server vulnerability in USN-3586-1 causes a denial of service, but it only affects Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
A remote attacker can exploit the DHCP server vulnerability to cause a denial of service.
The affected software packages are isc-dhcp-client, isc-dhcp-relay, isc-dhcp-server, and isc-dhcp-server-ldap.
To fix the DHCP vulnerabilities, update the affected software packages to the specified versions.