Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
https://kb.isc.org/article/AA-00714
https://kb.isc.org/article/AA-00712
https://kb.isc.org/article/AA-00737
http://www.vuxml.org/freebsd/c7fa3618-d5ff-11e1-90a2-000c299b62e1.html
Insight
The following packages are affected:
isc-dhcp41-server
isc-dhcp42-server
CVE-2012-3570
Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fault and daemon exit) via a crafted client identifier parameter.
CVE-2012-3571
ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
CVE-2012-3954
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
Severity
Classification
-
CVE CVE-2012-3570, CVE-2012-3571, CVE-2012-3954 -
CVSS Base Score: 6.1
AV:A/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities