Lucene search

K
ibmIBM6ACEF64072FEBB835E0DC33E95E66BF2764FB36F8CA32C3E3721959A4BBB3921
HistorySep 17, 2021 - 9:17 p.m.

Security Bulletin: ISC DHCP for IBM i is affected by CVE-2021-25217

2021-09-1721:17:32
www.ibm.com
14
isc dhcp
ibm i
denial of service
vulnerability
ptf
fix
cve-2021-25217

EPSS

0.003

Percentile

68.3%

Summary

ISC DHCP on IBM i is vulnerable to the issue described in the vulnerability details section. IBM i has addressed the vulnerability in the ISC DHCP implementation.

Vulnerability Details

CVEID:CVE-2021-25217
**DESCRIPTION:**ISC DHCP is vulnerable to a denial of service, caused by a buffer overrun in program code used to read and parse stored leases. A remote attacker from within the local network could exploit this vulnerability to cause a crash in the DHCP server or DHCP client.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/202604 for the current score.
CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM i 7.4
IBM i 7.3
IBM i 7.2
IBM i 7.1

Remediation/Fixes

The issue can be fixed by applying a PTF to IBM i.

Releases 7.4, 7.3, 7.2, and 7.1 of IBM i are supported and will be fixed.

The IBM i PTF numbers containing the fix for the CVE are:

Release 7.4 - SI76506
Release 7.3 - SI76507
Release 7.2 - SI76509
Release 7.1 - SI76508

https://www.ibm.com/support/fixcentral

_Important note: _IBM recommends that all users running unsupported versions of affected products upgrade to supported and fixed version of affected products.

Workarounds and Mitigations

None