CVE-2012-3955
ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 21.65% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- isc/dhcp · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-October/088882.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/086992.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088220.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00088.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00103.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00105.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0504.htmlThird Party Advisory
- http://secunia.com/advisories/51318Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201301-06.xmlThird Party Advisory
- http://www.debian.org/security/2012/dsa-2551Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:153Third Party Advisory
- http://www.securityfocus.com/bid/55530Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1027528Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1571-1Third Party Advisory
- https://blogs.oracle.com/sunsecurity/entry/cve_2012_3955_denial_ofThird Party Advisory
- https://kb.isc.org/article/AA-00779Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-October/088882.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/086992.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088220.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00088.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00103.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00105.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0504.htmlThird Party Advisory
- http://secunia.com/advisories/51318Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201301-06.xmlThird Party Advisory
- http://www.debian.org/security/2012/dsa-2551Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:153Third Party Advisory
- http://www.securityfocus.com/bid/55530Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1027528Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1571-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.