Back to Database
Status published
Low
CVE-2012-3954
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before...
Vulnerability Description
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-3954
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securitytracker.com/id?1027300
- http://www.debian.org/security/2012/dsa-2516
- http://rhn.redhat.com/errata/RHSA-2012-1141.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:116
- http://lists.opensuse.org/opensuse-updates/2012-08/msg00030.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:115
- http://www.debian.org/security/2012/dsa-2519
- http://www.ubuntu.com/usn/USN-1519-1
- https://kb.isc.org/article/AA-00737
- http://security.gentoo.org/glsa/glsa-201301-06.xml
- http://www.securityfocus.com/bid/54665
More from isc
View All →CVE-2018-5736
An error in zone database reference counting can lead to...
Medium
5.3
CVE-2016-9444
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5,...
High
7.5
CVE-2016-9147
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows...
High
7.5
CVE-2016-9131
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5,...
High
7.5
CVE-2016-8864
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4,...
High
7.5
Affected Vendor
Affected Software
dhcp, debian linux, ubuntu linux
Vulnerable Versions:
4.1.0, 4.1.1, 4.1.2, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.1-esv, 6.0, 7.0, 11.04, 11.10, 12.04
Timeline
Official Publish:
July 25th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.