<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ISC DHCP DoS vulnerability]]></title><description><![CDATA[<p dir="auto">Please take note of this recently announced denial-of-service vulnerability of ISC dhcpd (pfSense runs v4.2.1-p1)</p>
<blockquote>
<p dir="auto">http://www.isc.org/software/dhcp/advisories/cve-2011-2748</p>
<p dir="auto">ISC DHCP Server Halt<br />
Two issues have been found in DHCP that could allow an attacker to cause the server to halt.<br />
CVE: CVE-2011-2748<br />
Document Version:  1.1<br />
Posting date: 10 Aug 2011<br />
Program Impacted: DHCP<br />
Versions affected:  3.1.0 through 3.1-ESV-R1 (R2 never released) 4.0 all versions (EOL) 4.1.0 through 4.1.2rc1 4.1-ESV through 4.1-ESV-R3b1 4.2.0 through 4.2.2rc1 All End-of-Life versions of DHCP server are likely to be affected and ISC recommends upgrading to supported versions.<br />
Severity:  High<br />
Exploitable:  Remotely<br />
Description:<br />
A pair of defects cause the server to halt upon processing certain packets. The patch is to properly discard or process those packets.</p>
<p dir="auto">Document ID: CVE-2011-2748, CVE-2011-2749</p>
<p dir="auto">CVSS Score: 7.8</p>
<p dir="auto">CVSS Equation: (AV:N/AC:L/Au:N/C:N/I:N/A:C)</p>
<p dir="auto">For more information on the Common Vulnerability Scoring System and to obtain your specific environmental score please visit: http://nvd.nist.gov/cvww.cfm?calculator&amp;adv&amp;version=vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)</p>
<p dir="auto">Workarounds:<br />
Limiting DHCP and Bootp packets to only within your administrative domain will limit exposure.</p>
<p dir="auto">Active exploits:<br />
ISC received a report for one of the flaws and discovered the other during testing. No public exploits using these bugs are known.<br />
Solution:<br />
Upgrade to: 3.1-ESV-R3, 4.1-ESV-R3 or 4.2.2</p>
<p dir="auto">Please note that this is the last update to 3.1-ESV as it will be End-of-Life after this release.</p>
<p dir="auto">Download these versions from https://www.isc.org/downloads/all</p>
<p dir="auto">Acknowledgment:<br />
Found by David Zych at University of Illinois</p>
<p dir="auto">Document Revision History</p>
<p dir="auto">1.0 27 July 2011 - Phase 1 disclosure</p>
<p dir="auto">1.1 09 August 2011 - Phase 2 and 3 disclosures</p>
</blockquote>
]]></description><link>https://forum.netgate.com/topic/36222/isc-dhcp-dos-vulnerability</link><generator>RSS for Node</generator><lastBuildDate>Mon, 11 May 2026 11:59:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/36222.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 11 Aug 2011 15:45:28 GMT</pubDate><ttl>60</ttl></channel></rss>