CVE-2020-7461: Buffer Overflow
In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, dhclient(8) fails to handle certain malformed input related to handling of DHCP option 119 resulting a heap overflow. The heap overflow could in principle be exploited to achieve remote code execution. The affected process runs with reduced privileges in a Capsicum sandbox, limiting the immediate impact of an exploit.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7461?
CVE-2020-7461 is a vulnerability in FreeBSD that allows for a heap overflow in the dhclient(8) due to handling of DHCP option 119.
What is the severity of CVE-2020-7461?
The severity of CVE-2020-7461 is high with a severity score of 7.3.
Which versions of FreeBSD are affected by CVE-2020-7461?
FreeBSD versions 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13 are affected by CVE-2020-7461.
How can I fix CVE-2020-7461 in FreeBSD?
To fix CVE-2020-7461 in FreeBSD, it is recommended to update to FreeBSD 12.1-STABLE r365010 or later, 11.4-STABLE r365011 or later, 12.1-RELEASE p9 or later, 11.4-RELEASE p3 or later, or 11.3-RELEASE p13 or later.
Where can I find more information about CVE-2020-7461?
You can find more information about CVE-2020-7461 in the following references: [1] [2].