Lucene search

K
cve[email protected]CVE-2009-0692
HistoryJul 14, 2009 - 8:30 p.m.

CVE-2009-0692

2009-07-1420:30:00
CWE-119
web.nvd.nist.gov
90
isc dhcp
cve-2009-0692
buffer overflow
security vulnerability
remote code execution

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.076 Low

EPSS

Percentile

94.2%

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

Affected configurations

NVD
Node
iscdhcpMatch2.0
OR
iscdhcpMatch3.0
OR
iscdhcpMatch3.1
OR
iscdhcpMatch4.0
OR
iscdhcpMatch4.1.0

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.076 Low

EPSS

Percentile

94.2%