Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-0702

6 documents6 sources
Severity
10.0CRITICAL
EPSS
31.7%
top 3.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 26
Latest updateMay 3

Description

Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS server response.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDisc/dhcpd3.0, 3.0.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-crjc-v7fx-459m: Format string vulnerabilities in the logging routines for dynamic DNS code (print2022-05-03
CVEList
CVE-2002-0702: Format string vulnerabilities in the logging routines for dynamic DNS code (print2002-07-23

💥Exploits & PoCs

1
Exploit-DB
ISC DHCPD 2.0/3.0.1 - NSUPDATE Remote Format String2002-05-08

📋Vendor Advisories

1
Red Hat
security flaw2004-11-02

💬Community

1
Bugzilla
CVE-2004-1006 security flaw2018-08-16
CVE-2002-0702 (CRITICAL CVSS 10) | Format string vulnerabilities in th | cvebase.io