PT-2015-3955 · Roy Marples+1 · Dhcpcd+1

Published

2015-07-30

·

Updated

2017-09-21

·

CVE-2014-7913

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dhcpcd versions prior to 6.9.1 dhcpcd 5.x
Description The issue arises from the misinterpretation of the return value of the snprintf function by the print option function in dhcp-common.c. This allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted message.
Recommendations For dhcpcd versions prior to 6.9.1, update to version 6.9.1 or later to resolve the issue. For dhcpcd 5.x, consider disabling the print option function as a temporary workaround until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1048
CVE-2014-7913
DLA-506-1
MGASA-2016-0190

Affected Products

Alt Linux
Dhcpcd