CVE-2022-2929
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/10/2022
Last modified:
07/11/2023
Description
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:isc:dhcp:*:*:*:*:*:*:*:* | 1.0.0 (including) | 4.1-esv (excluding) |
| cpe:2.3:a:isc:dhcp:*:*:*:*:*:*:*:* | 4.2.0 (including) | 4.4.3 (including) |
| cpe:2.3:a:isc:dhcp:4.1-esv:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r10:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r10_b1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r10_rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r10b1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r10rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r11:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r11_b1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r11_rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r11_rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r11b1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r11rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:isc:dhcp:4.1-esv:r11rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://kb.isc.org/docs/cve-2022-2929
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
- https://security.gentoo.org/glsa/202305-22



