CVE-2009-0692
ISC DHCP dhclient < 3.1.2p1 - Remote Buffer Overflow (PoC)
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.
Desbordamiento de búfer basado en pila en el método script_write_params en client/dhclient.c en ISC DHCP dhclient v4.1 anteriores a v4.1.0p1, v4.0 anteriores a v4.0.1p1, v3.1 anteriores a v3.1.2p1, v3.0, y v2.0 permite a servidores DHCP remotos ejecutar código arbitrario a través de una opción manipulada subnet-mask.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-02-22 CVE Reserved
- 2009-07-14 CVE Published
- 2009-07-27 First Exploit
- 2023-09-01 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-121: Stack-based Buffer Overflow
CAPEC
References (38)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/9265 | 2009-07-27 |
URL | Date | SRC |
---|---|---|
https://www.isc.org/node/468 | 2017-09-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 2.0 Search vendor "Isc" for product "Dhcp" and version "2.0" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0 Search vendor "Isc" for product "Dhcp" and version "3.0" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.1 Search vendor "Isc" for product "Dhcp" and version "3.1" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.0 Search vendor "Isc" for product "Dhcp" and version "4.0" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 4.1.0 Search vendor "Isc" for product "Dhcp" and version "4.1.0" | - |
Affected
|