HIGH · 10.0

CVE-2004-0460

Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbi...

Vulnerability Description

Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
InfobloxDns One Appliance2.3.1_r5
IscDhcpd3.0.1
SuseSuse Email Serveriii
SuseSuse Linux Admin-Cd For FirewallAll versions
SuseSuse Linux Connectivity ServerAll versions
SuseSuse Linux Database ServerAll versions
SuseSuse Linux Firewall CdAll versions
SuseSuse Linux Office ServerAll versions
MandrakesoftMandrake Linux9.0
RedhatFedora Corecore_2.0
SuseSuse Linux7

References

FAQ

What is CVE-2004-0460?

CVE-2004-0460 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbi...

How severe is CVE-2004-0460?

CVE-2004-0460 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0460?

Check the references section above for vendor advisories and patch information. Affected products include: Infoblox Dns One Appliance, Isc Dhcpd, Suse Suse Email Server, Suse Suse Linux Admin-Cd For Firewall, Suse Suse Linux Connectivity Server.