9.8
CVSSv3

CVE-2019-11766

Published: 05/05/2019 Updated: 27/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

dhcp6.c in dhcpcd prior to 6.11.7 and 7.x prior to 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dhcpcd project dhcpcd

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #928056 dhcpcd5: CVE-2019-11578: auth: Use consttime_memequal to avoid latency attack Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sat, 27 Apr 2019 01:57:01 UTC Severity: serious Tags: f ...
Debian Bug report logs - #928440 dhcpcd5: CVE-2019-11766: DHCPv6: Potential read overflow with D6_OPTION_PD_EXCLUDE Package: dhcpcd5; Maintainer for dhcpcd5 is Scott Leggett <scott@slidau>; Source for dhcpcd5 is src:dhcpcd5 (PTS, buildd, popcon) Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sa ...
Debian Bug report logs - #928104 dhcpcd5: CVE-2019-11579: DHCP: Fix a potential 1 byte read overflow with DHO_OPTSOVERLOADED Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sat, 27 Apr 2019 01:57:01 UTC Severity: s ...
Debian Bug report logs - #928105 dhcpcd5: CVE-2019-11577: DHCPv6: Fix a potential buffer overflow reading NA/TA addresses Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: "Timo Sigurdsson" <public_timos@silentcreekde> Date: Sat, 27 Apr 2019 01:57:01 UTC Severity: seri ...