CVE-2003-0039
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/02/2003
Last modified:
03/04/2025
Description
ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:isc:dhcpd:3.0.1:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc10:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc2:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc3:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc4:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc5:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc6:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc7:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc8:*:*:*:*:*:* | ||
cpe:2.3:a:isc:dhcpd:3.0.1:rc9:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://cc.turbolinux.com/security/TLSA-2003-26.txt
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000616
- http://marc.info/?l=bugtraq&m=104310927813830&w=2
- http://www.debian.org/security/2003/dsa-245
- http://www.kb.cert.org/vuls/id/149953
- http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html
- http://www.redhat.com/support/errata/RHSA-2003-034.html
- http://www.securityfocus.com/bid/6628
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11187
- http://cc.turbolinux.com/security/TLSA-2003-26.txt
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000616
- http://marc.info/?l=bugtraq&m=104310927813830&w=2
- http://www.debian.org/security/2003/dsa-245
- http://www.kb.cert.org/vuls/id/149953
- http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html
- http://www.redhat.com/support/errata/RHSA-2003-034.html
- http://www.securityfocus.com/bid/6628
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11187