CVE-2007-5365
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
- Affected products
- Debian, Dhcp, Dhcp-Client-Udeb, Dhcp-Relay, Dhcpd
- Debian Debian Linux
- = 3.1, 4.0
- Openbsd
- = 4.0, 4.1, 4.2
- Redhat Enterprise Linux
- = 2.1
- Redhat Linux Advanced Workstation
- = 2.1
- Sun Opensolaris
- = snv_01, snv_02, snv_03, snv_04, snv_05, snv_06, snv_07, snv_08, snv_09, snv_10, snv_11, snv_12, snv_13, snv_14, snv_15, snv_16, snv_17, snv_18, snv_19, snv_20, snv_21, snv_22, snv_23, snv_24, snv_25, snv_26, snv_27, snv_28, snv_29, snv_30, snv_31, snv_32, snv_33
- CVSS 2.0
- 7.2 HIGH
- EPSS
- 80.3% (100th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2007-10-11
CVE-2007-5365 at NVD
5 known exploits for CVE-2007-5365
Proof-of-concept code and exploit modules indexed by Sploitus