Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-0062
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0062

Description:
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/33102

UBUNTU
  http://www.ubuntu.com/usn/usn-543-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html

ST
  1018717

SAID
  Secunia Advisory: SA31396
  Secunia Advisory: SA27706
  Secunia Advisory: SA27694
  Secunia Advisory: SA34263
  Secunia Advisory: SA26890

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2009:153

ISS
  http://www.iss.net/threats/275.html

GENTOO
  http://security.gentoo.org/glsa/glsa-200711-23.xml
  http://security.gentoo.org/glsa/glsa-200808-05.xml

FULLDISC
  http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html

CONFIRM
  http://www.vmware.com/support/player2/doc/releasenotes_player2.html
  http://www.vmware.com/support/server/doc/releasenotes_server.html
  http://wiki.rpath.com/Advisories:rPSA-2009-0041
  http://bugs.gentoo.org/show_bug.cgi?id=227135
  http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
  http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html
  http://www.vmware.com/support/ace/doc/releasenotes_ace.html
  http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html
  http://www.vmware.com/support/player/doc/releasenotes_player.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/501759/100/0/threaded

BID
  25729


Return to the previous page.