Vulnerability Description
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.
CVSS Score
7.5
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dhcpcd Project | Dhcpcd | <= 6.9.4 |
Related Weaknesses (CWE)
References
- http://roy.marples.name/projects/dhcpcd/info/595883e2a431f65d8fabf33059aa4689ccaPatchVendor Advisory
- http://roy.marples.name/projects/dhcpcd/timeline?r=trunk&nd&c=2016-01-07+16%3A47Release NotesVendor Advisory
- http://www.openwall.com/lists/oss-security/2016/01/07/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/07/4Mailing ListThird Party Advisory
- http://www.securitytracker.com/id/1034601
- https://security.gentoo.org/glsa/201606-07
- http://roy.marples.name/projects/dhcpcd/info/595883e2a431f65d8fabf33059aa4689ccaPatchVendor Advisory
- http://roy.marples.name/projects/dhcpcd/timeline?r=trunk&nd&c=2016-01-07+16%3A47Release NotesVendor Advisory
- http://www.openwall.com/lists/oss-security/2016/01/07/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/07/4Mailing ListThird Party Advisory
- http://www.securitytracker.com/id/1034601
- https://security.gentoo.org/glsa/201606-07
FAQ
What is CVE-2016-1504?
CVE-2016-1504 is a vulnerability with a CVSS score of 7.5 (HIGH). dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.
How severe is CVE-2016-1504?
CVE-2016-1504 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1504?
Check the references section above for vendor advisories and patch information. Affected products include: Dhcpcd Project Dhcpcd.