CVE-2007-5365

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
11/10/2007
Last modified:
09/04/2025

Description

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:4.0:*:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:4.1:*:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:4.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
cpe:2.3:o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_01:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_01:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_02:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_02:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_03:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_03:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_04:*:sparc:*:*:*:*:*


References to Advisories, Solutions, and Tools