ISC DHCP是美国Internet Systems Consortium(ISC)公司的一套开源的动态主机配置协议服务器软件。 ISC DHCP 4.1.0版本至4.1-ESV-R15版本、4.2.0版本至4.2.8版本和4.3.0版本至4.3.6版本中存在远程拒绝服务漏洞,该漏洞源于程序没有正确地清除已关闭的OMAPI连接。远程攻击者可利用该漏洞造成拒绝服务(资源耗尽)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-3143 | An error in TSIG authentication can permit unauthorized dynamic updates | |
| CVE-2018-5741 | Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their | |
| CVE-2018-5740 | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named | |
| CVE-2018-5739 | Failure to release memory may exhaust system resources | |
| CVE-2018-5738 | Some versions of BIND can improperly permit recursive query service to unauthorized client | |
| CVE-2018-5737 | BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other | |
| CVE-2018-5734 | A malformed request can trigger an assertion failure in badcache.c | |
| CVE-2018-5733 | A malicious client can overflow a reference counter in ISC dhcpd | |
| CVE-2017-3145 | Improper fetch cleanup sequencing in the resolver can cause named to crash | |
| CVE-2016-9778 | An error handling certain queries using the nxdomain-redirect feature could cause a REQUIR | |
| CVE-2017-3142 | An error in TSIG authentication can permit unauthorized zone transfers | |
| CVE-2017-3141 | Windows service and uninstall paths are not quoted when BIND is installed | |
| CVE-2017-3140 | An error processing RPZ rules can cause named to loop endlessly after handling a query | |
| CVE-2017-3138 | named exits with a REQUIRE assertion failure if it receives a null command string on its c | |
| CVE-2017-3137 | A response packet can cause a resolver to terminate when processing an answer containing a | |
| CVE-2017-3136 | An error handling synthesized records could cause an assertion failure when using DNS64 wi | |
| CVE-2017-3135 | Combination of DNS64 and RPZ Can Lead to Crash |
No comments yet