CVE-2016-2774
Published · Updated
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 74%
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
2 products (6 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
no_fix_planned: Will not fix
Fixed
8 products (320 components)
Red Hat Enterprise Linux Client (v. 7) · Red Hat Enterprise Linux Client Optional (v. 7) · Red Hat Enterprise Linux ComputeNode (v. 7) · Red Hat Enterprise Linux ComputeNode Optional (v. 7) · Red Hat Enterprise Linux Server (v. 7) · and others 3
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.
Affected products
n/a · n/aReferences
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183458.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/183640.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00066.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2590.htmlhttps://kb.isc.org/article/AA-01354https://lists.debian.org/debian-lts-announce/2019/11/msg00023.htmlhttps://usn.ubuntu.com/3586-1/http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/84208http://www.securitytracker.com/id/1035196