CVE-2007-5365: Buffer Overflow
Stack-based buffer overflow in the consoptions function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5365?
The severity of CVE-2007-5365 is critical due to the potential for remote code execution or denial of service.
How do I fix CVE-2007-5365?
To fix CVE-2007-5365, update the affected DHCP server implementation to the latest version that includes the security patch.
Which systems are affected by CVE-2007-5365?
CVE-2007-5365 affects OpenBSD versions 4.0 through 4.2 and other DHCP server implementations based on ISC DHCP-2.
What types of attacks can exploit CVE-2007-5365?
CVE-2007-5365 can be exploited through specially crafted DHCP requests leading to a stack-based buffer overflow.
Is there a workaround for CVE-2007-5365?
A potential workaround for CVE-2007-5365 includes disabling the DHCP server if an immediate upgrade is not feasible.