Back to Database
Status published
High
CVE-2011-2748
The server in ISC DHCP 3.x and 4.x before 4.2.2,...
Vulnerability Description
The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2748
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.ubuntu.com/usn/USN-1190-1
- http://redmine.pfsense.org/issues/1888
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065176.html
- http://secunia.com/advisories/45595
- http://lists.opensuse.org/opensuse-updates/2011-09/msg00014.html
- http://www.debian.org/security/2011/dsa-2292
- http://www.redhat.com/support/errata/RHSA-2011-1160.html
- http://securitytracker.com/id?1025918
- http://secunia.com/advisories/45817
- http://www.securityfocus.com/bid/49120
- http://www.isc.org/files/release-notes/DHCP%204.1-ESV-R3.html
- http://www.isc.org/files/release-notes/DHCP%203.1-ESV-R3_0.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69139
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://secunia.com/advisories/45582
- https://bugzilla.redhat.com/attachment.cgi?id=517665&action=diff
- http://secunia.com/advisories/45918
- http://www.isc.org/software/dhcp/advisories/cve-2011-2748
- http://security.gentoo.org/glsa/glsa-201301-06.xml
- http://www.isc.org/files/release-notes/DHCP%204.2.2_0.html
- http://secunia.com/advisories/45639
- https://bugzilla.redhat.com/show_bug.cgi?id=729382
- http://secunia.com/advisories/45629
- https://hermes.opensuse.org/messages/11695711
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:128
- http://secunia.com/advisories/46780
More from isc
View All →CVE-2018-5736
An error in zone database reference counting can lead to...
Medium
5.3
CVE-2016-9444
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5,...
High
7.5
CVE-2016-9147
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows...
High
7.5
CVE-2016-9131
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5,...
High
7.5
CVE-2016-8864
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4,...
High
7.5
Affected Vendor
Affected Software
dhcp, ubuntu linux, debian linux
Vulnerable Versions:
3.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.1, 3.1-esv, 3.1.0, 3.1.1, 3.1.2, 3.1.3, 4.0, 4.0-esv, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.1-esv, 4.1.0, 4.1.1, 4.1.2, 4.2.0, 4.2.1, 8.04, 10.04, 10.10, 11.04, 5.0, 6.0, 7.0
Timeline
Official Publish:
August 15th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.