Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW
Vulnerability Description
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting as or impersonating a DHCPv6 server can trigger dhcp6_deprecatedele() to free a delegated child address while an outer TAILQ_FOREACH_SAFE iterator in dhcp6_deprecateaddrs() still holds the freed pointer, causing a use-after-free when TAILQ_REMOVE is reached.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
释放后使用
Vulnerability Title
NetworkConfiguration dhcpcd 资源管理错误漏洞
Vulnerability Description
NetworkConfiguration dhcpcd是NetworkConfiguration团队的一款DHCP客户端软件。 NetworkConfiguration dhcpcd 10.3.2及之前版本存在资源管理错误漏洞,该漏洞源于存在堆释放后重用问题,可能导致未经身份验证的同链路攻击者通过发送特制的带RFC6603 OPTION_PD_EXCLUDE且优先和有效期限设为零的DHCPv6 RENEW回复,导致守护进程崩溃。
CVSS Information
N/A
Vulnerability Type
N/A