← All CVEs

CVE-2004-0461

high · 10

The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.

10
CVSS
16.8%
EPSS (exploit prob.)
97th
EPSS percentile
2004-08-06
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
infobloxdns_one_appliance2.3.1_r5
infobloxdns_one_appliance2.4.0.8
infobloxdns_one_appliance2.4.0.8a
iscdhcpd3.0.1
iscdhcpd3.0.1
susesuse_email_serveriii
susesuse_linux_admin-cd_for_firewallall versions
susesuse_linux_connectivity_serverall versions
susesuse_linux_database_serverall versions
susesuse_linux_firewall_cdall versions
susesuse_linux_office_serverall versions
mandrakesoftmandrake_linux9.0
mandrakesoftmandrake_linux9.1
mandrakesoftmandrake_linux9.1
mandrakesoftmandrake_linux9.2
mandrakesoftmandrake_linux9.2
mandrakesoftmandrake_linux10.0
mandrakesoftmandrake_linux10.0
redhatfedora_corecore_2.0
susesuse_linux7
susesuse_linux8
susesuse_linux8.0
susesuse_linux8.0
susesuse_linux8.1
susesuse_linux8.2
susesuse_linux9.0
susesuse_linux9.0
susesuse_linux9.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0461