CVE-2007-5365

UnknownEPSS 80.27%

Last modified

CVE-2007-5365 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.. EPSS estimates a 80.27% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.

Metrics

EPSS Probability
80.27%

99.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
DebianDebian Linux3.1—
DebianDebian Linux4.0—
OpenbsdOpenbsd4.0—
OpenbsdOpenbsd4.1—
OpenbsdOpenbsd4.2—
RedhatEnterprise Linux2.1—
RedhatLinux Advanced Workstation2.1—
SunOpensolarissnv_01—
SunOpensolarissnv_02—
SunOpensolarissnv_03—
SunOpensolarissnv_04—
SunOpensolarissnv_05—
SunOpensolarissnv_06—
SunOpensolarissnv_07—
SunOpensolarissnv_08—
SunOpensolarissnv_09—
SunOpensolarissnv_10—
SunOpensolarissnv_11—
SunOpensolarissnv_12—
SunOpensolarissnv_13—
SunOpensolarissnv_14—
SunOpensolarissnv_15—
SunOpensolarissnv_16—
SunOpensolarissnv_17—
SunOpensolarissnv_18—
SunOpensolarissnv_19—
SunOpensolarissnv_20—
SunOpensolarissnv_21—
SunOpensolarissnv_22—
SunOpensolarissnv_23—
SunOpensolarissnv_24—
SunOpensolarissnv_25—
SunOpensolarissnv_26—
SunOpensolarissnv_27—
SunOpensolarissnv_28—
SunOpensolarissnv_29—
SunOpensolarissnv_30—
SunOpensolarissnv_31—
SunOpensolarissnv_32—
SunOpensolarissnv_33—
SunOpensolarissnv_34—
SunOpensolarissnv_35—
SunOpensolarissnv_36—
SunOpensolarissnv_37—
SunOpensolarissnv_38—
SunOpensolarissnv_39—
SunOpensolarissnv_40—
SunOpensolarissnv_41—
SunOpensolarissnv_42—
SunOpensolarissnv_43—

Showing 50 of 116 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-5365?
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
How severe is CVE-2007-5365?
Severity scoring for CVE-2007-5365 is pending analysis. The EPSS model estimates a 80.27% probability of exploitation in the next 30 days.
How do I fix CVE-2007-5365?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2007

Are you affected by CVE-2007-5365?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST