CVE-2007-0062
Summary
| CVE | CVE-2007-0062 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-21 19:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: CWE-119 | CWE-189 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Ace | 1.0.3 | All | All | All |
| Application | Vmware | Ace | 2.0 | All | All | All |
| Application | Vmware | Player | 1.0.4 | All | All | All |
| Application | Vmware | Player | 2.0 | All | All | All |
| Application | Vmware | Server | 1.0.3 | All | All | All |
| Application | Vmware | Vmware Workstation | 6.0.1 | All | All | All |
| Application | Vmware | Workstation | 3.4 | All | All | All |
| Application | Vmware | Workstation | 4.0 | All | All | All |
| Application | Vmware | Workstation | 4.0.1 | All | All | All |
| Application | Vmware | Workstation | 4.0.2 | All | All | All |
| Application | Vmware | Workstation | 4.5.2 | All | All | All |
| Application | Vmware | Workstation | 5.5.0_build_13124 | All | All | All |
| Application | Vmware | Workstation | 5.5.1 | All | All | All |
| Application | Vmware | Workstation | 5.5.1_build_19175 | All | All | All |
| Application | Vmware | Workstation | 5.5.3_build_34685 | All | All | All |
| Application | Vmware | Workstation | 5.5.3_build_42958 | All | All | All |
| Application | Vmware | Workstation | 5.5.4 | All | All | All |
| Application | Vmware | Workstation | 5.5.4_build_44386 | All | All | All |
| Application | Vmware | Workstation | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories:rPSA-2009-0041 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| Bug 339561 – CVE-2007-0062 dhcpd possible DoS via large max-message-size option | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| VMware Player Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:005 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| VMWare DHCP Server Remote Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Patch |
| Gentoo Linux Documentation -- VMware Workstation and Player: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [Full-Disclosure] Mailing List Charter | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| Support / Security / Advisories / / MDVSA-2009:153 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| ISC DHCP: Denial of Service — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| VMware Server Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| USN-543-1: VMWare vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| rPath update for dhclient, dhcp, and libdhcp4client - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VMware ACE Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| Gentoo update for vmware - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo update for dhcp - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VMware DHCP Bugs Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMware Workstation 6 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| VMware Player Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| Gentoo Bug 227135 - net-misc/dhcp <3.1.1 dhcp-max-message-size DoS (CVE-2007-0062) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Ubuntu update for vmware - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VMware Workstation 5.5 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| VMWare Products Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| VMware Workstation DHCP Server Multiple Remote Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| VMware ACE Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-06-03 | Mark J Cox | The Red Hat Security Response Team has rated this issue as having low security impact. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 2.1, 3, 4, or 5: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-0062 |
There are currently no legacy QID mappings associated with this CVE.