HIGH · 10.0

CVE-2004-0461

The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe ...

Vulnerability Description

The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
InfobloxDns One Appliance2.3.1_r5
IscDhcpd3.0.1
SuseSuse Email Serveriii
SuseSuse Linux Admin-Cd For FirewallAll versions
SuseSuse Linux Connectivity ServerAll versions
SuseSuse Linux Database ServerAll versions
SuseSuse Linux Firewall CdAll versions
SuseSuse Linux Office ServerAll versions
MandrakesoftMandrake Linux9.0
RedhatFedora Corecore_2.0
SuseSuse Linux7

References

FAQ

What is CVE-2004-0461?

CVE-2004-0461 is a vulnerability with a CVSS score of 10.0 (HIGH). The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe ...

How severe is CVE-2004-0461?

CVE-2004-0461 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0461?

Check the references section above for vendor advisories and patch information. Affected products include: Infoblox Dns One Appliance, Isc Dhcpd, Suse Suse Email Server, Suse Suse Linux Admin-Cd For Firewall, Suse Suse Linux Connectivity Server.