TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2017-3144

HIGH
7.5

Beschreibung

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.

CVE Details

CVSS v3.1 Bewertung7.5
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht1/16/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

canonical:ubuntu_linuxdebian:debian_linuxisc:dhcpredhat:enterprise_linux_desktopredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eusredhat:enterprise_linux_server_tusredhat:enterprise_linux_workstation

Schwachen (CWE)

CWE-400

Referenzen

http://www.securityfocus.com/bid/102726(security-officer@isc.org)
https://kb.isc.org/docs/aa-01541(security-officer@isc.org)
https://usn.ubuntu.com/3586-1/(security-officer@isc.org)
http://www.securityfocus.com/bid/102726(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1040194(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2018:0158(af854a3a-2127-422b-91ae-364da2661108)
https://kb.isc.org/docs/aa-01541(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3586-1/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2018/dsa-4133(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.