CVE-2009-0692

EUVD-2009-0692
Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
iscdhcp
2.0
iscdhcp
3.0
iscdhcp
3.1
iscdhcp
4.0
iscdhcp
4.1.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dhcp
dapper
not-affected
hardy
dne
intrepid
dne
jaunty
dne
dhcp3
dapper
Fixed 3.0.3-6ubuntu7.1
released
hardy
Fixed 3.0.6.dfsg-1ubuntu9.1
released
intrepid
Fixed 3.1.1-1ubuntu2.2
released
jaunty
Fixed 3.1.1-5ubuntu8.2
released
karmic
Fixed 3.1.2-1ubuntu7.1
released
References