CVE-2007-0062

UnknownEPSS 7.62%

Last modified

CVE-2007-0062 is a vulnerability of currently unknown severity. Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.. EPSS estimates a 7.62% chance of exploitation in the next 30 days.

Description

Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.

Metrics

EPSS Probability
7.62%

93.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
VmwareAce1.0.3
VmwareAce2.0
VmwarePlayer1.0.4
VmwarePlayer2.0
VmwareServer1.0.3
VmwareVmware Workstation6.0.1
VmwareWorkstation3.4
VmwareWorkstation4.0
VmwareWorkstation4.0.1
VmwareWorkstation4.0.2
VmwareWorkstation4.5.2
VmwareWorkstation5.5.0_build_13124
VmwareWorkstation5.5.1
VmwareWorkstation5.5.1_build_19175
VmwareWorkstation5.5.3_build_34685
VmwareWorkstation5.5.3_build_42958
VmwareWorkstation5.5.4
VmwareWorkstation5.5.4_build_44386
VmwareWorkstation6.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-0062?
Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.
How severe is CVE-2007-0062?
Severity scoring for CVE-2007-0062 is pending analysis. The EPSS model estimates a 7.62% probability of exploitation in the next 30 days.
How do I fix CVE-2007-0062?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-0062?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST