Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.871705
Category:Red Hat Local Security Checks
Title:RedHat Update for dhcp RHSA-2016:2590-02
Summary:The remote host is missing an update for the 'dhcp'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'dhcp'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The Dynamic Host Configuration Protocol
(DHCP) is a protocol that allows individual devices on an IP network to get their
own network configuration information, including an IP address, a subnet mask,
and a broadcast address. The dhcp packages provide a relay agent and ISC DHCP
service required to enable and administer DHCP on a network.

Security Fix(es):

* A resource-consumption flaw was discovered in the DHCP server. dhcpd did
not restrict the number of open connections to OMAPI and failover ports. A
remote attacker able to establish TCP connections to one of these ports
could use this flaw to cause dhcpd to exit unexpectedly, stop responding
requests, or exhaust system sockets (denial of service). (CVE-2016-2774)

Red Hat would like to thank ISC for reporting this issue.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.3 Release Notes linked from the References section.

Affected Software/OS:
dhcp on Red Hat Enterprise Linux Server (v. 7)

Solution:
Please Install the Updated Packages.

CVSS Score:
7.1

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-2774
BugTraq ID: 84208
http://www.securityfocus.com/bid/84208
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183640.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183458.html
https://lists.debian.org/debian-lts-announce/2019/11/msg00023.html
RedHat Security Advisories: RHSA-2016:2590
http://rhn.redhat.com/errata/RHSA-2016-2590.html
http://www.securitytracker.com/id/1035196
SuSE Security Announcement: openSUSE-SU-2016:1843 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-07/msg00066.html
https://usn.ubuntu.com/3586-1/
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.