5
CVSSv2

CVE-2009-1892

Published: 17/07/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote malicious users to cause a denial of service (daemon crash) via unspecified requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc dhcp 3.1.1

isc dhcp 3.0.4

isc dhcp 3.0.4_b1

isc dhcp 3.0.4_b2

isc dhcp 3.0.4_b3

Vendor Advisories

Debian Bug report logs - #539492 CVE-2009-1892: DoS Package: dhcp3-server; Maintainer for dhcp3-server is (unknown); Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sat, 1 Aug 2009 12:45:02 UTC Severity: grave Tags: patch, security Fixed in version 312p1-2 Done: Andrew Pollock <apollock@debianorg& ...
Several remote vulnerabilities have been discovered in ISC's DHCP implementation: CVE-2009-0692 It was discovered that dhclient does not properly handle overlong subnet mask options, leading to a stack-based buffer overflow and possible arbitrary code execution CVE-2009-1892 Christoph Biedl discovered that the DHCP server may terminate when recei ...