CVE-2004-0461Improper Restriction of Operations within the Bounds of a Memory Buffer in Dhcpd

3 documents3 sources
Severity
10.0CRITICALNVD
EPSS
12.1%
top 6.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateApr 29

Description

The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages6 packages

NVDisc/dhcpd3.0.1
NVDsuse/suse_linux7 versions+6
NVDredhat/fedora_corecore_2.0
NVDinfoblox/dns_one_appliance2.3.1_r5, 2.4.0.8, 2.4.0.8a+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wmcx-jvg5-m384: The DHCP daemon (DHCPD) for ISC DHCP 32022-04-29
CVEList
CVE-2004-0461: The DHCP daemon (DHCPD) for ISC DHCP 32004-06-24
CVE-2004-0461 — ISC Dhcpd vulnerability | cvebase