CVE-2012-3571 EXPLOIT
6.1
MEDIUM · CVSS 2.0 · EPSS 13% (pctl 96)
Patch early
A public exploit exists.
Description
ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
Scoring
| CVSS | 6.1 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:A/AC:L/Au:N/C:N/I:N/A:C |
| EPSS | 12.99% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-07-25 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| isc | dhcp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ISC DHCP 4.x - Multiple Denial of Service Vulnerabilities | 2012-07-25 |
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.opensuse.org/opensuse-updates/2012-08/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2012-1140.html
- http://rhn.redhat.com/errata/RHSA-2012-1141.html
- http://security.gentoo.org/glsa/glsa-201301-06.xml
- http://www.debian.org/security/2012/dsa-2516
- http://www.debian.org/security/2012/dsa-2519
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:115
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:116
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/54665
- http://www.ubuntu.com/usn/USN-1519-1
- https://kb.isc.org/article/AA-00712
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.opensuse.org/opensuse-updates/2012-08/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2012-1140.html
- http://rhn.redhat.com/errata/RHSA-2012-1141.html
- http://security.gentoo.org/glsa/glsa-201301-06.xml
- http://www.debian.org/security/2012/dsa-2516
- http://www.debian.org/security/2012/dsa-2519
→ the Explorer · watch your stack · NVD