VulnerabilityModified
CVE-2015-8605
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
MEDIUM 6.5EPSS 76.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 76.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 76.45% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- sophos/unified threat management up2date · isc/dhcp · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175594.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00162.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00168.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3442Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlThird Party Advisory
- http://www.securityfocus.com/bid/80703Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034657Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2868-1Third Party Advisory
- https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/Third Party Advisory
- https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/Third Party Advisory
- https://kb.isc.org/article/AA-01334Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175594.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00162.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00168.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3442Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlThird Party Advisory
- http://www.securityfocus.com/bid/80703Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034657Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2868-1Third Party Advisory
- https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/Third Party Advisory
- https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/Third Party Advisory
- https://kb.isc.org/article/AA-01334Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.