CVE Database
/

CVE-2018-5733

Back to search

CVE-2018-5733

Published: Jan 16, 2019

Modified: Apr 25, 2025

PUBLISHED

CVSS v3.0

5.9

MEDIUM

Description

A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0.

VendorProductVersions

ISC

ISC DHCP

affected
ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

RHSA-2018:0469
vendor-advisory
x_refsource_REDHAT
DSA-4133
vendor-advisory
x_refsource_DEBIAN
USN-3586-2
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:0483
vendor-advisory
x_refsource_REDHAT
USN-3586-1
vendor-advisory
x_refsource_UBUNTU
103188
vdb-entry
x_refsource_BID
1040437
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now