PT-2015-3955 · Roy Marples+1 · Dhcpcd+1

Publicado

2015-07-30

·

Atualizado

2017-09-21

·

CVE-2014-7913

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dhcpcd versions prior to 6.9.1 dhcpcd 5.x
Description The issue arises from the misinterpretation of the return value of the snprintf function by the print option function in dhcp-common.c. This allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted message.
Recommendations For dhcpcd versions prior to 6.9.1, update to version 6.9.1 or later to resolve the issue. For dhcpcd 5.x, consider disabling the print option function as a temporary workaround until a patch is available.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1048
CVE-2014-7913
DLA-506-1
MGASA-2016-0190

Produtos afetados

Alt Linux
Dhcpcd