CVE-2004-1006

CWE-2306 documents6 sources
Severity
10.0CRITICAL
EPSS
7.7%
top 8.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 1
Latest updateApr 29

Description

Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDisc/dhcpd7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3f5j-qwg9-83wr: Format string vulnerability in the log functions in dhcpd for dhcp 22022-04-29
CVEList
CVE-2004-1006: Format string vulnerability in the log functions in dhcpd for dhcp 22004-11-19

📋Vendor Advisories

1
Red Hat
security flaw2004-11-02

📐Framework References

1
CWE
Improper Handling of Missing Values

💬Community

1
Bugzilla
CVE-2004-1006 security flaw2018-08-16
CVE-2004-1006 (CRITICAL CVSS 10) | Format string vulnerability in the | cvebase.io