CVE-2018-5733

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-5733
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-5733.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-5733
Related
Published
2019-01-16T20:29:00Z
Modified
2025-04-26T00:52:57.644240Z
Downstream
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0.

References

Affected packages

Alpine:v3.10 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.11 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.12 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.13 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.14 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.15 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.16 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.17 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.18 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.19 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Alpine:v3.20 / dhcp

Package

Name
dhcp
Purl
pkg:apk/alpine/dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-r0

Affected versions

4.*

4.1.0-r0
4.1.0_p1-r0
4.1.0_p1-r1
4.1.0_p1-r2
4.1.0_p1-r3
4.1.0_p1-r4
4.1.0_p1-r5
4.1.0_p1-r6
4.1.0_p1-r7
4.1.0_p1-r8
4.1.0_p1-r9
4.1.0_p1-r10
4.1.1_p1-r0
4.1.1_p1-r1
4.2.0-r0
4.2.0_p1-r0
4.2.0_p2-r0
4.2.1-r0
4.2.1_p1-r0
4.2.1_p1-r1
4.2.2-r0
4.2.3-r0
4.2.3_p1-r0
4.2.3_p2-r0
4.2.3_p2-r1
4.2.4-r0
4.2.4_p1-r0
4.2.4_p1-r1
4.2.4_p2-r0
4.2.5-r0
4.2.5_p1-r0
4.2.5_p1-r1
4.2.5_p1-r2
4.3.0-r0
4.3.0-r1
4.3.1-r0
4.3.1-r1
4.3.2-r0
4.3.3-r0
4.3.3_p1-r0
4.3.4-r0
4.3.4-r1
4.3.4-r2
4.3.4-r3
4.3.5-r0

Debian:11 / isc-dhcp

Package

Name
isc-dhcp
Purl
pkg:deb/debian/isc-dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.5-3.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / isc-dhcp

Package

Name
isc-dhcp
Purl
pkg:deb/debian/isc-dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.5-3.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / isc-dhcp

Package

Name
isc-dhcp
Purl
pkg:deb/debian/isc-dhcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.5-3.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / gitlab.isc.org/isc-projects/dhcp

Affected ranges

Type
GIT
Repo
https://gitlab.isc.org/isc-projects/dhcp
Events
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Introduced
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Introduced
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected

Affected versions

Other

v4_3_0
v4_3_1
v4_3_1b1
v4_3_1rc1
v4_3_2
v4_3_2b1
v4_3_2rc1
v4_3_2rc2
v4_3_3
v4_3_3b1
v4_3_4
v4_3_4b1
v4_3_5
v4_3_5b1
v4_3_6
v4_3_6b1
v4_4_0
v4_4_0b1_f1

v4_3_2.*

v4_3_2.pre-beta