CVE-2003-0026
Summary
| CVE | CVE-2003-0026 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-01-17 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Isc | Dhcpd | 3.0 | All | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc1 | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc2 | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc3 | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc4 | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc5 | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc6 | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc7 | All | All |
| Application | Isc | Dhcpd | 3.0.1 | rc8 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - ISC DHCPD Minires Library Buffer Overflows Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| OpenPKG Corporation: Security: Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.openpkg.com | |
| ISC DHCPD NSUPDATE MiniRes Library Remote Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.suse.com | |
| Debian -- Security Information -- DSA-231-1 dhcp3 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch, Vendor Advisory |
| CERT/CC Vulnerability Note VU#284857 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch, Vendor Advisory |
| N-031: Buffer Overflows in ISC DHCPD Minires Library | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| Neohapsis Archives - Bugtraq - [securityslackware.com: [slackware-security] New DHCP packages available] - From whitevampire_at_mindless.com | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CERT Advisory CA-2003-01 Buffer Overflows in ISC DHCPD Minires Library | af854a3a-2127-422b-91ae-364da2661108 | www.cert.org | Patch, Third Party Advisory, US Government Resource |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.