UBUNTU-CVE-2018-5732

Source
https://ubuntu.com/security/CVE-2018-5732
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-5732.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-5732
Related
Published
2018-03-01T00:00:00Z
Modified
2018-03-01T00:00:00Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0

References

Affected packages

Ubuntu:14.04:LTS / isc-dhcp

Package

Name
isc-dhcp
Purl
pkg:deb/ubuntu/isc-dhcp?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.4-7ubuntu12.12

Affected versions

4.*

4.2.4-7ubuntu8
4.2.4-7ubuntu9
4.2.4-7ubuntu10
4.2.4-7ubuntu11
4.2.4-7ubuntu12
4.2.4-7ubuntu12.1
4.2.4-7ubuntu12.2
4.2.4-7ubuntu12.3
4.2.4-7ubuntu12.4
4.2.4-7ubuntu12.5
4.2.4-7ubuntu12.6
4.2.4-7ubuntu12.7
4.2.4-7ubuntu12.8
4.2.4-7ubuntu12.9
4.2.4-7ubuntu12.10

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-client"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-client-dbg"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-client-dbgsym"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-client-noddns"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-client-udeb"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-client-udeb-dbgsym"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-common"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-common-dbgsym"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-dev"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-relay"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-relay-dbg"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-relay-dbgsym"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-server"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-server-dbg"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-server-dbgsym"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-server-ldap"
        },
        {
            "binary_version": "4.2.4-7ubuntu12.12",
            "binary_name": "isc-dhcp-server-ldap-dbgsym"
        }
    ]
}

Ubuntu:16.04:LTS / isc-dhcp

Package

Name
isc-dhcp
Purl
pkg:deb/ubuntu/isc-dhcp?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.3-5ubuntu12.9

Affected versions

4.*

4.3.1-5ubuntu3
4.3.1-5ubuntu4
4.3.1-5ubuntu5
4.3.3-5ubuntu1
4.3.3-5ubuntu2
4.3.3-5ubuntu4
4.3.3-5ubuntu5
4.3.3-5ubuntu7
4.3.3-5ubuntu8
4.3.3-5ubuntu9
4.3.3-5ubuntu10
4.3.3-5ubuntu11
4.3.3-5ubuntu12
4.3.3-5ubuntu12.1
4.3.3-5ubuntu12.3
4.3.3-5ubuntu12.4
4.3.3-5ubuntu12.6
4.3.3-5ubuntu12.7

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-client"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-client-dbgsym"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-client-ddns"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-client-ddns-dbgsym"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-client-udeb"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-client-udeb-dbgsym"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-common"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-common-dbgsym"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-dbg"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-dev"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-dev-dbgsym"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-relay"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-relay-dbgsym"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-server"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-server-dbgsym"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-server-ldap"
        },
        {
            "binary_version": "4.3.3-5ubuntu12.9",
            "binary_name": "isc-dhcp-server-ldap-dbgsym"
        }
    ]
}

Ubuntu:18.04:LTS / isc-dhcp

Package

Name
isc-dhcp
Purl
pkg:deb/ubuntu/isc-dhcp?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.5-3ubuntu5

Affected versions

4.*

4.3.5-3ubuntu2
4.3.5-3ubuntu3
4.3.5-3ubuntu4

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-client"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-client-dbgsym"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-client-ddns"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-client-ddns-dbgsym"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-client-udeb"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-common"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-dev"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-relay"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-relay-dbgsym"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-server"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-server-dbgsym"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-server-ldap"
        },
        {
            "binary_version": "4.3.5-3ubuntu5",
            "binary_name": "isc-dhcp-server-ldap-dbgsym"
        }
    ]
}