ISC DHCP DHCPv6 Vulnerability
The Internet Systems Consortium, the makers of the open source DHCP server, indicated the DHCPv6 service may crash after processing a DHCPv6 decline message. This vulnerability has been assigned CVE 2011-0413 and affect version 4.0.x-4.2.x and maybe remotely exploitable.
Note: This DoS only affects DHCPv6 servers and there is currently no workaround.
[1] https://lists.isc.org/pipermail/isc-os-security/2011-January/000000.html
[2] http://www.kb.cert.org/vuls/id/686084
-----------
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot org
Keywords: DHCPv6 DoS
2 comment(s)
×
Diary Archives
Comments
Oleksiy
Jan 28th 2011
1 decade ago
Jan 28 2011 - "... Solution: The vendor has issued a fix (4.1.2-P1, 4.1-ESV-R1, or 4.2.1b1).
The vendor's advisory is available at:
Vendor URL: www.isc.org/software/dhcp/advisories/cve-2011-0413
"... Solution: Upgrade to 4.1.2-P1, 4.1-ESV-R1, or 4.2.1b1..."
.
PC.Tech
Jan 28th 2011
1 decade ago