ISC Memory.C DHCP Server Denial Of Service Vulnerability

BID:19348

CVE-2006-3122 |

Info

ISC Memory.C DHCP Server Denial Of Service Vulnerability

Bugtraq ID: 19348
Class: Boundary Condition Error
CVE: CVE-2006-3122
Remote: Yes
Local: No
Published: Aug 04 2006 12:00AM
Updated: Oct 24 2006 11:33PM
Credit: Justin Winschief and Andrew Steets have been credited with the discovery of this vulnerability.
Vulnerable: Xerox WorkCentre Pro 275
Xerox WorkCentre Pro 265
Xerox WorkCentre Pro 255
Xerox WorkCentre Pro 245
Xerox WorkCentre Pro 238
Xerox WorkCentre Pro 232
Xerox WorkCentre 275
Xerox WorkCentre 265
Xerox WorkCentre 255
Xerox WorkCentre 245
Xerox WorkCentre 238
Xerox WorkCentre 232
Xerox Document Centre 555
Xerox Document Centre 545
Xerox Document Centre 535
Xerox Document Centre 490 ST
Xerox Document Centre 490
Xerox Document Centre 480 ST
Xerox Document Centre 480 DC
Xerox Document Centre 480
Xerox Document Centre 470 ST
Xerox Document Centre 470
Xerox Document Centre 460 ST
Xerox Document Centre 460
Xerox Document Centre 440 ST
Xerox Document Centre 440 DC
Xerox Document Centre 440
Xerox Document Centre 432 ST
Xerox Document Centre 432
Xerox Document Centre 430
Xerox Document Centre 426
Xerox Document Centre 425 ST
Xerox Document Centre 425
Xerox Document Centre 420 ST
Xerox Document Centre 420
Xerox Document Centre 340 ST
Xerox Document Centre 340
Xerox Document Centre 332 ST
Xerox Document Centre 332
Xerox Document Centre 265 ST
Xerox Document Centre 265
Xerox Document Centre 255 ST
Xerox Document Centre 255
Xerox Document Centre 240 ST
Xerox Document Centre 240
Xerox Document Centre 230 ST
Xerox Document Centre 230
Xerox Document Centre 220 ST
Xerox Document Centre 220
OpenBSD OpenBSD 3.9
OpenBSD OpenBSD 3.8
ISC DHCPD 2.0.pl5
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
ISC DHCPD 2.0
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 ia-32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Not Vulnerable:

Discussion

ISC Memory.C DHCP Server Denial Of Service Vulnerability

ISC DHCP server is prone to a denial-of-service vulnerability. This issue occurs when an automatic IP address is assigned to a system.

An attacker can exploit this issue to crash the DHCP server, causing a denial-of-service condititon.

This issue affects version 2 releases of DHCP; version 3 releases are reportedly not affected.

Exploit / POC

ISC Memory.C DHCP Server Denial Of Service Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]

Solution / Fix

ISC Memory.C DHCP Server Denial Of Service Vulnerability

Solution:
The vendor has released an advisory to address the issue. The vendor has also stated that DHCP 2.x is end-of-life software, so users may want to upgrade to a current version. Please see the referenced advisories for more information.


OpenBSD OpenBSD 3.9

OpenBSD OpenBSD 3.8

ISC DHCPD 2.0.pl5

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report