CVE-2007-0062
published 2007-09-21CVE-2007-0062: Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.62%
93.9th percentile
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace | — | — |
| vmware | ace | — | — |
| vmware | player | — | — |
| vmware | player | — | — |
| vmware | server | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
vendor_vmware·2008-06-04·CVSS 2.6
CVE-2006-1721 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
VMSA-2008-0009: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security Advisory VMware Security AdvisoryAdvisory ID: VMware Security AdvisorySynopsis: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security AdvisoryIssue date: VMware Security AdvisoryUpdated on:
CVEs: CVE-2006-1721, CVE-2007-4772, CVE-2007-5378, CVE-2007-5671, CVE-2008-0062, CVE-2008-0063, CVE-2008-0553, CVE-2008-0888, CVE-2
Ubuntu
VMWare vulnerabilities
vendor_ubuntu·2007-11-15·CVSS 10.0
CVE-2007-0062 [CRITICAL] VMWare vulnerabilities
Title: VMWare vulnerabilities
Summary: VMWare vulnerabilities
Neel Mehta and Ryan Smith discovered that the VMWare Player DHCP server
did not correctly handle certain packet structures. Remote attackers
could send specially crafted packets and gain root privileges.
(CVE-2007-0061, CVE-2007-0062, CVE-2007-0063)
Rafal Wojtczvk discovered multiple memory corruption issues in VMWare
Player. Attackers with administrative privileges in a guest operating
system could cause a denial of service or possibly execute arbitrary
code on the host operating system. (CVE-2007-4496, CVE-2007-4497)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
dhcpd possible DoS via large max-message-size option
vendor_redhat·2007-09-19·CVSS 10.0
CVE-2007-0062 [CRITICAL] dhcpd possible DoS via large max-message-size option
dhcpd possible DoS via large max-message-size option
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.
Statement: The Red Hat Product Security has rated this issue as having low security impact. The risks associated with fi
GHSA
GHSA-g7fq-vjjh-pwc3: Integer overflow in the ISC dhcpd 3
ghsa_unreviewed·2022-05-01
CVE-2007-0062 [HIGH] CWE-119 GHSA-g7fq-vjjh-pwc3: Integer overflow in the ISC dhcpd 3
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0062 dhcpd possible DoS via large max-message-size option
bugzilla·2007-10-19·CVSS 10.0
CVE-2007-0062 [CRITICAL] CVE-2007-0062 dhcpd possible DoS via large max-message-size option
CVE-2007-0062 dhcpd possible DoS via large max-message-size option
ISC dhcpd is prone to denial of service attack (daemon crash) when DHCP client
specifies large value for dhcp-max-message-size in the request.
Problem only occurs when dhcpd is configured to provide clients with very large
amount of DHCP options. Such configurations seems very unlikely to exist in the
real deployments.
Discussion:
Created attachment 241731
ISC patch for dhcp 3.0.x
Thanks to Evan Hunt for providing this patch!
Patch itself is bit long, as it has some unrelated changes too, like formatting
updates and re-wording of some comments.
---
This patch is a bit large. Can we have it without the formatting changes? If
not, I'll go through it and reduce it to just the security fix.
I'd like to get updates out
Bugzilla
CVE-2007-5365 dhcpd stack-based buffer overlow
bugzilla·2007-10-11·CVSS 10.0
CVE-2007-5365 [CRITICAL] CVE-2007-5365 dhcpd stack-based buffer overlow
CVE-2007-5365 dhcpd stack-based buffer overlow
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5365 to the following vulnerability:
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
References:
http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1962
http://www.openbsd.org/errata42.html#001_dhcpd
http://secunia.com/advisories/27160
http://www.securityfocus.com/bid/25984
Discussion:
OpenBSD's dhcpd is based on ISC dhcpd 2.x. We ship dhcpd 2.0pl5 in Red Hat
Enterprise Linux 2.1, which seems to be affected by this
http://bugs.gentoo.org/show_bug.cgi?id=227135http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.htmlhttp://secunia.com/advisories/26890http://secunia.com/advisories/27694http://secunia.com/advisories/27706http://secunia.com/advisories/31396http://secunia.com/advisories/34263http://security.gentoo.org/glsa/glsa-200711-23.xmlhttp://security.gentoo.org/glsa/glsa-200808-05.xmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0041http://www.iss.net/threats/275.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:153http://www.securityfocus.com/archive/1/501759/100/0/threadedhttp://www.securityfocus.com/bid/25729http://www.securitytracker.com/id?1018717http://www.ubuntu.com/usn/usn-543-1http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2007/3229https://bugzilla.redhat.com/show_bug.cgi?id=339561https://exchange.xforce.ibmcloud.com/vulnerabilities/33102http://bugs.gentoo.org/show_bug.cgi?id=227135http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.htmlhttp://secunia.com/advisories/26890http://secunia.com/advisories/27694http://secunia.com/advisories/27706http://secunia.com/advisories/31396http://secunia.com/advisories/34263http://security.gentoo.org/glsa/glsa-200711-23.xmlhttp://security.gentoo.org/glsa/glsa-200808-05.xmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0041http://www.iss.net/threats/275.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:153http://www.securityfocus.com/archive/1/501759/100/0/threadedhttp://www.securityfocus.com/bid/25729http://www.securitytracker.com/id?1018717http://www.ubuntu.com/usn/usn-543-1http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2007/3229https://bugzilla.redhat.com/show_bug.cgi?id=339561https://exchange.xforce.ibmcloud.com/vulnerabilities/33102
2007-09-21
Published