Synced 17 Jun 2026 22:27 UTC Account
← All products

CVE-2013-2494

MEDIUM severity · CVSS 4.9 · Memory corruption
4.9CVSS MEDIUM

Summary

libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine running a dhcpd process, a related issue to CVE-2013-2266.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges required
User interaction
Confidentiality impactNone
Integrity impactNone
Availability impact
Exploit probability (EPSS)1%

AV:N/AC:H/Au:S/C:N/I:N/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Additional information