CVE-2004-1006: Critical severity ISC dhcpd vulnerability
Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1006?
CVE-2004-1006 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2004-1006?
To fix CVE-2004-1006, upgrade to a patched version of ISC DHCP Server that addresses the format string vulnerability.
Which versions of ISC DHCP Server are affected by CVE-2004-1006?
CVE-2004-1006 affects ISC DHCP Server versions 2.0.pl5 and 3.0, as well as various 3.0 beta and release candidates.
What is the nature of the vulnerability in CVE-2004-1006?
CVE-2004-1006 is a format string vulnerability in the log functions of the dhcpd allowing arbitrary code execution.
Can CVE-2004-1006 be exploited remotely?
Yes, CVE-2004-1006 can be exploited remotely through specially crafted DNS messages sent to vulnerable DHCP servers.