First published: Thu Jul 30 2015(Updated: )
The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android before 5.1 and other products, misinterprets the return value of the snprintf function, which allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted message.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
dhcpcd | <=6.9.0 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7913 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2014-7913, update dhcpcd to the latest version beyond 6.9.0 or apply patches provided by the vendor.
CVE-2014-7913 affects dhcpcd versions up to and including 6.9.0.
Yes, CVE-2014-7913 can lead to a denial of service due to memory corruption.
Android versions prior to 5.1 may potentially be vulnerable to CVE-2014-7913 when utilizing affected dhcpcd builds.