{
  "threat_severity" : "Low",
  "public_date" : "2012-09-12T00:00:00Z",
  "bugzilla" : {
    "description" : "dhcp: reduced expiration time of an IPv6 lease may cause dhcpd to crash",
    "id" : "856766",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=856766"
  },
  "cvss" : {
    "cvss_base_score" : "2.9",
    "cvss_scoring_vector" : "AV:A/AC:M/Au:N/C:N/I:N/A:P",
    "status" : "verified"
  },
  "details" : [ "ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.", "A flaw was found in the way the dhcpd daemon handled the expiration time of IPv6 leases. If dhcpd's configuration was changed to reduce the default IPv6 lease time, lease renewal requests for previously assigned leases could cause dhcpd to crash." ],
  "statement" : "This issue does not affect the version of dhcp as shipped with Red Hat Enterprise Linux 5.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2013-02-20T00:00:00Z",
    "advisory" : "RHSA-2013:0504",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "dhcp-12:4.1.1-34.P1.el6"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "dhcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2012-3955\nhttps://nvd.nist.gov/vuln/detail/CVE-2012-3955" ],
  "name" : "CVE-2012-3955",
  "csaw" : false
}