Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2012-3955 |
CWE-ID | CWE-20 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
dhcp (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU33931
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2012-3955
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.
MitigationInstall update from vendor's website.
Vulnerable software versionsdhcp (Alpine package): 4.1.1-r0 - 4.2.4_p1-r1
CPE2.3https://git.alpinelinux.org/aports/commit/?id=4b933e8d614263914d7f0e433784bde15aaf250c
https://git.alpinelinux.org/aports/commit/?id=4be6396274c20b99643b279900876f51aa1c6da5
https://git.alpinelinux.org/aports/commit/?id=0f30b46b4e0fe507508d7bcd9fd32a25c2bec2a9
https://git.alpinelinux.org/aports/commit/?id=bec5f6f816d4046c9a47dad89f460b198e511f8f
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.