Vulnerabilities > CVE-2003-0026 - Remote Buffer Overflow vulnerability in ISC DHCPD NSUPDATE MiniRes Library

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
isc
nessus

Summary

Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.

Vulnerable Configurations

Part Description Count
Application
Isc
9

Nessus

  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2003-007.NASL
    descriptionSeveral potential vulnerabilities were detected by the ISC (Internet Software Consortium) in their dhcp server software. The vulnerabilities affect the minires library and may be exploitable as stack buffer overflows, which could lead to remote code execution. All Mandrake Linux users are encouraged to upgrade; only Mandrake Linux 8.0 came with dhcp 2.x and is not vulnerable.
    last seen2020-06-01
    modified2020-06-02
    plugin id13992
    published2004-07-31
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/13992
    titleMandrake Linux Security Advisory : dhcp (MDKSA-2003:007)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-231.NASL
    descriptionThe Internet Software Consortium discovered several vulnerabilities during an audit of the ISC DHCP Daemon. The vulnerabilities exist in error handling routines within the minires library and may be exploitable as stack overflows. This could allow a remote attacker to execute arbitrary code under the user id the dhcpd runs under, usually root. Other DHCP servers than dhcp3 doesn
    last seen2020-06-01
    modified2020-06-02
    plugin id15068
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15068
    titleDebian DSA-231-1 : dhcp3 - stack overflows

Redhat

advisories
rhsa
idRHSA-2003:011