CVE-2004-0460: Buffer Overflow
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0460?
The severity of CVE-2004-0460 is high due to the potential for remote code execution and denial of service.
How do I fix CVE-2004-0460?
To fix CVE-2004-0460, upgrade to a patched version of ISC DHCP, specifically versions after 3.0.1rc13.
What software is affected by CVE-2004-0460?
CVE-2004-0460 affects ISC DHCP versions 3.0.1rc12 and 3.0.1rc13, as well as various Linux distributions that incorporate these versions.
What types of attacks can be executed using CVE-2004-0460?
Attackers can exploit CVE-2004-0460 to cause a denial of service or potentially execute arbitrary code on the affected DHCP server.
Is CVE-2004-0460 still a relevant vulnerability today?
While CVE-2004-0460 is an older vulnerability, it remains relevant for legacy systems that have not been updated or patched.