HIGH
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code
Published Jun 24, 2004
10.0
HIGHCVSS 2.0
EPSS 16.77%
Description
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.
Affected products
No data.
Configuration 1
AND
OR
- 2.3.1_r5
- 2.4.0.8
- 2.4.0.8a
OR
- 3.0.1
- 3.0.1
- iii
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
OR
- 9.0
- 9.1
- 9.1
- 9.2
- 9.2
- 10.0
- 10.0
- core_2.0
- 7
- 8
- 8.0
- 8.0
- 8.1
- 8.2
- 9.0
- 9.0
- 9.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (11)
- http://marc.info/?l=bugtraq&m=108795911203342&w=2 mailing-listx_refsource_BUGTRAQ
- http://marc.info/?l=bugtraq&m=108843959502356&w=2 mailing-listx_refsource_BUGTRAQ
- http://marc.info/?l=bugtraq&m=108938625206063&w=2 mailing-listx_refsource_BUGTRAQ
- http://secunia.com/advisories/23265 third-party-advisoryx_refsource_SECUNIA
- http://www.kb.cert.org/vuls/id/654390 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:061 vendor-advisoryx_refsource_MANDRAKE
- http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/10591 vdb-entryx_refsource_BIDPatchVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-174A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf x_refsource_CONFIRM
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16476 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 24, 2004
Updated Aug 8, 2024
Reserved May 12, 2004
Link CVE-2004-0461
CISA Vulnrichment
Updated n/a