Show plain JSON{"id": "CVE-2006-3122", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2006-08-09T22:04:00.000", "references": [{"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=380273", "source": "security@debian.org"}, {"url": "http://secunia.com/advisories/21345", "tags": ["Patch", "Vendor Advisory"], "source": "security@debian.org"}, {"url": "http://secunia.com/advisories/21363", "tags": ["Patch", "Vendor Advisory"], "source": "security@debian.org"}, {"url": "http://secunia.com/advisories/21655", "source": "security@debian.org"}, {"url": "http://securitytracker.com/id?1016755", "source": "security@debian.org"}, {"url": "http://www.debian.org/security/2006/dsa-1143", "tags": ["Patch"], "source": "security@debian.org"}, {"url": "http://www.openbsd.org/errata.html#dhcpd", "source": "security@debian.org"}, {"url": "http://www.securityfocus.com/bid/19348", "source": "security@debian.org"}, {"url": "http://www.vupen.com/english/advisories/2006/3158", "tags": ["Vendor Advisory"], "source": "security@debian.org"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-399"}]}], "descriptions": [{"lang": "en", "value": "The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) via a DHCPDISCOVER packet with a 32 byte client-identifier, which causes the packet to be interpreted as a corrupt uid and causes the server to exit with \"corrupt lease uid.\""}, {"lang": "es", "value": "La funci\u00f3n supersede_lease en memory.c de ISC DHCP (dhcpd) server 2.0p15 permite a atacantes remotos provocar una denegaci\u00f3n de servicio (cierre de aplicaci\u00f3n) mediante un paquete DHCPDISCOVER con un identificador de cliente de 32 bytes, lo que provoca que el paquete sea interpretado como un uid corrupto y provoca que el server se cierre con un mensaje \"corrupt lease uid\"."}], "lastModified": "2011-06-13T04:00:00.000", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:isc:dhcpd:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9ED82578-CA62-4CA8-8633-B9E8DD133050", "versionEndIncluding": "2.0pl5"}], "operator": "OR"}]}], "sourceIdentifier": "security@debian.org"}