5.7
CVSSv2

CVE-2015-8605

Published: 14/01/2016 Updated: 01/04/2020
CVSS v2 Base Score: 5.7 | Impact Score: 6.9 | Exploitability Score: 5.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 507
Vector: AV:A/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

ISC DHCP 4.x prior to 4.1-ESV-R12-P1, 4.2.x, and 4.3.x prior to 4.3.3-P1 allows remote malicious users to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.

Vulnerable Product Search on Vulmon Subscribe to Product

sophos unified threat management up2date

isc dhcp 4.0.0

isc dhcp 4.0.1

isc dhcp 4.0.2

isc dhcp 4.0.3

isc dhcp 4.1-esv

isc dhcp 4.1.0

isc dhcp 4.1.1

isc dhcp 4.1.2

isc dhcp 4.2.0

isc dhcp 4.2.1

isc dhcp 4.2.2

isc dhcp 4.2.3

isc dhcp 4.2.4

isc dhcp 4.2.5

isc dhcp 4.2.6

isc dhcp 4.2.7

isc dhcp 4.2.8

isc dhcp 4.3.0

isc dhcp 4.3.1

isc dhcp 4.3.2

isc dhcp 4.3.3

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 15.04

canonical ubuntu linux 15.10

Vendor Advisories

Debian Bug report logs - #810875 isc-dhcp: CVE-2015-8605: UDP payload length not properly checked Package: src:isc-dhcp; Maintainer for src:isc-dhcp is Debian ISC DHCP Maintainers <isc-dhcp@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 13 Jan 2016 05:51:05 UTC Severity: grave ...
DHCP server, client, or relay could be made to crash if they received specially crafted network traffic ...
ISC DHCP 4x before 41-ESV-R12-P1 and 42x and 43x before 433-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet ...
ISC DHCP 4x before 41-ESV-R12-P1, 42x, and 43x before 433-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet ...