10

CVE-2004-0460

Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.

Data is provided by the National Vulnerability Database (NVD)
InfobloxDns One Appliance Version2.3.1_r5
InfobloxDns One Appliance Version2.4.0.8
InfobloxDns One Appliance Version2.4.0.8a
IscDhcpd Version3.0.1 Updaterc12
IscDhcpd Version3.0.1 Updaterc13
SuseSuse Email Server Versioniii
MandrakesoftMandrake Linux Version9.0
MandrakesoftMandrake Linux Version9.1
MandrakesoftMandrake Linux Version9.1 Editionppc
MandrakesoftMandrake Linux Version9.2
MandrakesoftMandrake Linux Version9.2 Editionamd64
MandrakesoftMandrake Linux Version10.0
MandrakesoftMandrake Linux Version10.0 Editionamd64
RedhatFedora Core Versioncore_2.0
SuseSuse Linux Version7 Editionenterprise_server
SuseSuse Linux Version8 Editionenterprise_server
SuseSuse Linux Version8.0
SuseSuse Linux Version8.0 Editioni386
SuseSuse Linux Version8.1
SuseSuse Linux Version8.2
SuseSuse Linux Version9.0
SuseSuse Linux Version9.0 Editionx86_64
SuseSuse Linux Version9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 63.05% 0.982
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C