CVE-2014-6060
published 2014-09-04CVE-2014-6060: The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED…
PriorityP49low3.3CVSS 2.0
AVAACLAuNCNINAP
EPSS
0.44%
35.2th percentile
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dhcpcd | < dhcpcd5 6.0.5-2 (bookworm) | dhcpcd5 6.0.5-2 (bookworm) |
| debian | dhcpcd5 | < dhcpcd5 6.0.5-2 (bookworm) | dhcpcd5 6.0.5-2 (bookworm) |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
| dhcpcd_project | dhcpcd | — | — |
CVSS provenance
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2j5q-4fj9-xmqw: The get_option function in dhcpcd 4
ghsa_unreviewed·2022-05-17
CVE-2014-6060 [LOW] GHSA-2j5q-4fj9-xmqw: The get_option function in dhcpcd 4
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.
OSV
CVE-2014-6060: The get_option function in dhcpcd 4
osv·2014-09-04·CVSS 3.3
CVE-2014-6060 [LOW] CVE-2014-6060: The get_option function in dhcpcd 4
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.
Debian
CVE-2014-6060: dhcpcd - The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote D...
vendor_debian·2014·CVSS 3.3
CVE-2014-6060 [LOW] CVE-2014-6060: dhcpcd - The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote D...
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0334.htmlhttp://roy.marples.name/projects/dhcpcd/ci/1d2b93aa5ce25a8a710082fe2d36a6bf7f5794d5?sbs=0http://source.android.com/security/bulletin/2016-04-02.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:171http://www.openwall.com/lists/oss-security/2014/07/30/5http://www.openwall.com/lists/oss-security/2014/09/01/11http://www.securityfocus.com/bid/68970http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.462420http://advisories.mageia.org/MGASA-2014-0334.htmlhttp://roy.marples.name/projects/dhcpcd/ci/1d2b93aa5ce25a8a710082fe2d36a6bf7f5794d5?sbs=0http://source.android.com/security/bulletin/2016-04-02.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:171http://www.openwall.com/lists/oss-security/2014/07/30/5http://www.openwall.com/lists/oss-security/2014/09/01/11http://www.securityfocus.com/bid/68970http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.462420
2014-09-04
Published