Buffer Overflow in ISC DHCP 3.0.1rc12 and 3.0.1rc13 Affects Logging Functions
CVE-2004-0460

Currently unrated

What is CVE-2004-0460?

A buffer overflow vulnerability exists in the logging mechanism of the ISC DHCP daemon, specifically in versions 3.0.1rc12 and 3.0.1rc13. This flaw allows attackers to exploit multiple hostname options within DHCP messages, such as DISCOVER and OFFER, leading to potential server crashes or even arbitrary code execution. By manipulating the length of strings written to log files, an attacker may disrupt service delivery and compromise system integrity.

References

EPSS Score

45% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.