Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-0461
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0461

Description:
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/16476

SUSE
  http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html

SAID
  Secunia Advisory: SA23265

MANDRAKE
  http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:061

CONFIRM
  http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf

CERT-VN
  654390

CERT
  http://www.us-cert.gov/cas/techalerts/TA04-174A.html

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=108938625206063&w=2
  http://marc.theaimsgroup.com/?l=bugtraq&m=108795911203342&w=2
  http://marc.theaimsgroup.com/?l=bugtraq&m=108843959502356&w=2

BID
  10591


Return to the previous page.