5
CVSSv2

CVE-2019-6470

Published: 01/11/2019 Updated: 06/11/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Builds of dhcpd versions prior to version 4.4.1 when using BIND versions 9.11.2 or later, or BIND versions with specific bug fixes backported to them. ISC does not have access to comprehensive version lists for all repackagings of dhcpd that are vulnerable. In particular, builds from other vendors may also be affected. Operators are advised to consult their vendor documentation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind

isc dhcpd

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

opensuse leap 15.1

opensuse leap 15.0

Vendor Advisories

Debian Bug report logs - #896122 isc-dhcp: CVE-2019-6470 Package: isc-dhcp-server; Maintainer for isc-dhcp-server is Debian ISC DHCP Maintainers <isc-dhcp@packagesdebianorg>; Source for isc-dhcp-server is src:isc-dhcp (PTS, buildd, popcon) Reported by: Giorgos Skafidas <giorgosskafidas@gmxcom> Date: Thu, 19 Apr 2 ...
Synopsis Moderate: dhcp security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for dhcp is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base sco ...
Synopsis Moderate: dhcp security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for dhcp is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base sco ...
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm All releases of dhcpd from ISC contain copies of this, and ot ...