Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.52427
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: isc-dhcp3-relay, isc-dhcp3-server
Resumen:The remote host is missing an update to the system;as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:
isc-dhcp3-relay
isc-dhcp3-server

CVE-2004-0460
Buffer overflow in the logging capability for the DHCP daemon (DHCPD)
for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause
a denial of service (server crash) and possibly execute arbitrary code
via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST,
(4) ACK, or (5) NAK messages, which can generate a long string when
writing to a log file.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2004-0460
BugTraq ID: 10590
http://www.securityfocus.com/bid/10590
Bugtraq: 20040622 DHCP Vuln // no code 0day // (Google Search)
http://marc.info/?l=bugtraq&m=108795911203342&w=2
Bugtraq: 20040628 ISC DHCP overflows (Google Search)
http://marc.info/?l=bugtraq&m=108843959502356&w=2
Bugtraq: 20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd) (Google Search)
http://marc.info/?l=bugtraq&m=108938625206063&w=2
Cert/CC Advisory: TA04-174A
http://www.us-cert.gov/cas/techalerts/TA04-174A.html
CERT/CC vulnerability note: VU#317350
http://www.kb.cert.org/vuls/id/317350
http://www.mandriva.com/security/advisories?name=MDKSA-2004:061
http://secunia.com/advisories/23265
SuSE Security Announcement: SuSE-SA:2004:019 (Google Search)
http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html
XForce ISS Database: dhcp-ascii-log-bo(16475)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16475
CopyrightCopyright (C) 2008 E-Soft Inc.

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.