Vulnerability Description
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Isc | Dhcp | >= 4.2.0, <= 4.2.8 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Server Tus | 7.4 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102726Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040194Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0158Third Party Advisory
- https://kb.isc.org/docs/aa-01541Vendor Advisory
- https://usn.ubuntu.com/3586-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4133Third Party Advisory
- http://www.securityfocus.com/bid/102726Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040194Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0158Third Party Advisory
- https://kb.isc.org/docs/aa-01541Vendor Advisory
- https://usn.ubuntu.com/3586-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4133Third Party Advisory
FAQ
What is CVE-2017-3144?
CVE-2017-3144 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1...
How severe is CVE-2017-3144?
CVE-2017-3144 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3144?
Check the references section above for vendor advisories and patch information. Affected products include: Isc Dhcp, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Aus, Redhat Enterprise Linux Server Eus.