CVE-2004-0461: Buffer Overflow
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0461?
CVE-2004-0461 is classified as a medium severity vulnerability due to the potential for a denial of service caused by buffer overflow.
How do I fix CVE-2004-0461?
To fix CVE-2004-0461, upgrade to a version of ISC DHCP that does not define vsnprintf to use the less safe vsprintf function.
Which software is affected by CVE-2004-0461?
CVE-2004-0461 affects ISC DHCP versions 3.0.1rc12 and 3.0.1rc13, along with specific versions of SUSE and Mandrake Linux.
What kind of attack does CVE-2004-0461 enable?
CVE-2004-0461 enables a denial of service attack via buffer overflow vulnerabilities.
Are older versions of DHCPD vulnerable to CVE-2004-0461?
Yes, older versions of DHCPD, specifically 3.0.1rc12 and 3.0.1rc13, are vulnerable to CVE-2004-0461.