CVE-2007-5365

Summary

CVECVE-2007-5365
StatePUBLISHED
Assignermitre
Source PriorityCVE Program / NVD first with legacy fallback
Published2007-10-11 10:17:00 UTC
Updated2026-04-23 00:35:47 UTC
DescriptionStack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.

Risk And Classification

Primary CVSS: v2.0 7.2 from [email protected]

AV:L/AC:L/Au:N/C:C/I:C/A:C

Problem Types: CWE-119 | n/a

CVSS v2.0 Breakdown

Access Vector
Local
Access Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:L/AC:L/Au:N/C:C/I:C/A:C

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Debian Debian Linux 3.1 All All All
Operating System Debian Debian Linux 4.0 All All All
Operating System Openbsd Openbsd 4.0 All All All
Operating System Openbsd Openbsd 4.1 All All All
Operating System Openbsd Openbsd 4.2 All All All
Operating System Redhat Enterprise Linux 2.1 All as All
Operating System Redhat Enterprise Linux 2.1 All es All
Operating System Redhat Linux Advanced Workstation 2.1 All itanium All
Operating System Sun Opensolaris snv_01 All sparc All
Operating System Sun Opensolaris snv_01 All x86 All
Operating System Sun Opensolaris snv_02 All sparc All
Operating System Sun Opensolaris snv_02 All x86 All
Operating System Sun Opensolaris snv_03 All sparc All
Operating System Sun Opensolaris snv_03 All x86 All
Operating System Sun Opensolaris snv_04 All sparc All
Operating System Sun Opensolaris snv_04 All x86 All
Operating System Sun Opensolaris snv_05 All sparc All
Operating System Sun Opensolaris snv_05 All x86 All
Operating System Sun Opensolaris snv_06 All sparc All
Operating System Sun Opensolaris snv_06 All x86 All
Operating System Sun Opensolaris snv_07 All sparc All
Operating System Sun Opensolaris snv_07 All x86 All
Operating System Sun Opensolaris snv_08 All sparc All
Operating System Sun Opensolaris snv_08 All x86 All
Operating System Sun Opensolaris snv_09 All sparc All
Operating System Sun Opensolaris snv_09 All x86 All
Operating System Sun Opensolaris snv_10 All sparc All
Operating System Sun Opensolaris snv_10 All x86 All
Operating System Sun Opensolaris snv_100 All sparc All
Operating System Sun Opensolaris snv_100 All x86 All
Operating System Sun Opensolaris snv_101 All sparc All
Operating System Sun Opensolaris snv_101 All x86 All
Operating System Sun Opensolaris snv_102 All sparc All
Operating System Sun Opensolaris snv_102 All x86 All
Operating System Sun Opensolaris snv_11 All sparc All
Operating System Sun Opensolaris snv_11 All x86 All
Operating System Sun Opensolaris snv_12 All sparc All
Operating System Sun Opensolaris snv_12 All x86 All
Operating System Sun Opensolaris snv_13 All sparc All
Operating System Sun Opensolaris snv_13 All x86 All
Operating System Sun Opensolaris snv_14 All sparc All
Operating System Sun Opensolaris snv_14 All x86 All
Operating System Sun Opensolaris snv_15 All sparc All
Operating System Sun Opensolaris snv_15 All x86 All
Operating System Sun Opensolaris snv_16 All sparc All
Operating System Sun Opensolaris snv_16 All x86 All
Operating System Sun Opensolaris snv_17 All sparc All
Operating System Sun Opensolaris snv_17 All x86 All
Operating System Sun Opensolaris snv_18 All sparc All
Operating System Sun Opensolaris snv_18 All x86 All
Operating System Sun Opensolaris snv_19 All sparc All
Operating System Sun Opensolaris snv_19 All x86 All
Operating System Sun Opensolaris snv_20 All sparc All
Operating System Sun Opensolaris snv_20 All x86 All
Operating System Sun Opensolaris snv_21 All sparc All
Operating System Sun Opensolaris snv_21 All x86 All
Operating System Sun Opensolaris snv_22 All sparc All
Operating System Sun Opensolaris snv_22 All x86 All
Operating System Sun Opensolaris snv_23 All sparc All
Operating System Sun Opensolaris snv_23 All x86 All
Operating System Sun Opensolaris snv_24 All sparc All
Operating System Sun Opensolaris snv_24 All x86 All
Operating System Sun Opensolaris snv_25 All sparc All
Operating System Sun Opensolaris snv_25 All x86 All
Operating System Sun Opensolaris snv_26 All sparc All
Operating System Sun Opensolaris snv_26 All x86 All
Operating System Sun Opensolaris snv_27 All sparc All
Operating System Sun Opensolaris snv_27 All x86 All
Operating System Sun Opensolaris snv_28 All sparc All
Operating System Sun Opensolaris snv_28 All x86 All
Operating System Sun Opensolaris snv_29 All sparc All
Operating System Sun Opensolaris snv_29 All x86 All
Operating System Sun Opensolaris snv_30 All sparc All
Operating System Sun Opensolaris snv_30 All x86 All
Operating System Sun Opensolaris snv_31 All sparc All
Operating System Sun Opensolaris snv_31 All x86 All
Operating System Sun Opensolaris snv_32 All sparc All
Operating System Sun Opensolaris snv_32 All x86 All
Operating System Sun Opensolaris snv_33 All sparc All
Operating System Sun Opensolaris snv_33 All x86 All
Operating System Sun Opensolaris snv_34 All sparc All
Operating System Sun Opensolaris snv_34 All x86 All
Operating System Sun Opensolaris snv_35 All sparc All
Operating System Sun Opensolaris snv_35 All x86 All
Operating System Sun Opensolaris snv_36 All sparc All
Operating System Sun Opensolaris snv_36 All x86 All
Operating System Sun Opensolaris snv_37 All sparc All
Operating System Sun Opensolaris snv_37 All x86 All
Operating System Sun Opensolaris snv_38 All sparc All
Operating System Sun Opensolaris snv_38 All x86 All
Operating System Sun Opensolaris snv_39 All sparc All
Operating System Sun Opensolaris snv_39 All x86 All
Operating System Sun Opensolaris snv_40 All sparc All
Operating System Sun Opensolaris snv_40 All x86 All
Operating System Sun Opensolaris snv_41 All sparc All
Operating System Sun Opensolaris snv_41 All x86 All
Operating System Sun Opensolaris snv_42 All sparc All
Operating System Sun Opensolaris snv_42 All x86 All
Operating System Sun Opensolaris snv_43 All sparc All
Operating System Sun Opensolaris snv_43 All x86 All
Operating System Sun Opensolaris snv_44 All sparc All
Operating System Sun Opensolaris snv_44 All x86 All
Operating System Sun Opensolaris snv_45 All sparc All
Operating System Sun Opensolaris snv_45 All x86 All
Operating System Sun Opensolaris snv_46 All sparc All
Operating System Sun Opensolaris snv_46 All x86 All
Operating System Sun Opensolaris snv_47 All sparc All
Operating System Sun Opensolaris snv_47 All x86 All
Operating System Sun Opensolaris snv_48 All sparc All
Operating System Sun Opensolaris snv_48 All x86 All
Operating System Sun Opensolaris snv_49 All sparc All
Operating System Sun Opensolaris snv_49 All x86 All
Operating System Sun Opensolaris snv_50 All sparc All
Operating System Sun Opensolaris snv_50 All x86 All
Operating System Sun Opensolaris snv_51 All sparc All
Operating System Sun Opensolaris snv_51 All x86 All
Operating System Sun Opensolaris snv_52 All sparc All
Operating System Sun Opensolaris snv_52 All x86 All
Operating System Sun Opensolaris snv_53 All sparc All
Operating System Sun Opensolaris snv_53 All x86 All
Operating System Sun Opensolaris snv_54 All sparc All
Operating System Sun Opensolaris snv_54 All x86 All
Operating System Sun Opensolaris snv_55 All sparc All
Operating System Sun Opensolaris snv_55 All x86 All
Operating System Sun Opensolaris snv_56 All sparc All
Operating System Sun Opensolaris snv_56 All x86 All
Operating System Sun Opensolaris snv_57 All sparc All
Operating System Sun Opensolaris snv_57 All x86 All
Operating System Sun Opensolaris snv_58 All sparc All
Operating System Sun Opensolaris snv_58 All x86 All
Operating System Sun Opensolaris snv_59 All sparc All
Operating System Sun Opensolaris snv_59 All x86 All
Operating System Sun Opensolaris snv_60 All sparc All
Operating System Sun Opensolaris snv_60 All x86 All
Operating System Sun Opensolaris snv_61 All sparc All
Operating System Sun Opensolaris snv_61 All x86 All
Operating System Sun Opensolaris snv_62 All sparc All
Operating System Sun Opensolaris snv_62 All x86 All
Operating System Sun Opensolaris snv_63 All sparc All
Operating System Sun Opensolaris snv_63 All x86 All
Operating System Sun Opensolaris snv_64 All sparc All
Operating System Sun Opensolaris snv_64 All x86 All
Operating System Sun Opensolaris snv_65 All sparc All
Operating System Sun Opensolaris snv_65 All x86 All
Operating System Sun Opensolaris snv_66 All sparc All
Operating System Sun Opensolaris snv_66 All x86 All
Operating System Sun Opensolaris snv_67 All sparc All
Operating System Sun Opensolaris snv_67 All x86 All
Operating System Sun Opensolaris snv_68 All sparc All
Operating System Sun Opensolaris snv_68 All x86 All
Operating System Sun Opensolaris snv_69 All sparc All
Operating System Sun Opensolaris snv_69 All x86 All
Operating System Sun Opensolaris snv_70 All sparc All
Operating System Sun Opensolaris snv_70 All x86 All
Operating System Sun Opensolaris snv_71 All sparc All
Operating System Sun Opensolaris snv_71 All x86 All
Operating System Sun Opensolaris snv_72 All sparc All
Operating System Sun Opensolaris snv_72 All x86 All
Operating System Sun Opensolaris snv_73 All sparc All
Operating System Sun Opensolaris snv_73 All x86 All
Operating System Sun Opensolaris snv_74 All sparc All
Operating System Sun Opensolaris snv_74 All x86 All
Operating System Sun Opensolaris snv_75 All sparc All
Operating System Sun Opensolaris snv_75 All x86 All
Operating System Sun Opensolaris snv_76 All sparc All
Operating System Sun Opensolaris snv_76 All x86 All
Operating System Sun Opensolaris snv_77 All sparc All
Operating System Sun Opensolaris snv_77 All x86 All
Operating System Sun Opensolaris snv_78 All sparc All
Operating System Sun Opensolaris snv_78 All x86 All
Operating System Sun Opensolaris snv_79 All sparc All
Operating System Sun Opensolaris snv_79 All x86 All
Operating System Sun Opensolaris snv_80 All sparc All
Operating System Sun Opensolaris snv_80 All x86 All
Operating System Sun Opensolaris snv_81 All sparc All
Operating System Sun Opensolaris snv_81 All x86 All
Operating System Sun Opensolaris snv_82 All sparc All
Operating System Sun Opensolaris snv_82 All x86 All
Operating System Sun Opensolaris snv_83 All sparc All
Operating System Sun Opensolaris snv_83 All x86 All
Operating System Sun Opensolaris snv_84 All sparc All
Operating System Sun Opensolaris snv_84 All x86 All
Operating System Sun Opensolaris snv_85 All sparc All
Operating System Sun Opensolaris snv_85 All x86 All
Operating System Sun Opensolaris snv_86 All sparc All
Operating System Sun Opensolaris snv_86 All x86 All
Operating System Sun Opensolaris snv_87 All sparc All
Operating System Sun Opensolaris snv_87 All x86 All
Operating System Sun Opensolaris snv_88 All sparc All
Operating System Sun Opensolaris snv_88 All x86 All
Operating System Sun Opensolaris snv_89 All sparc All
Operating System Sun Opensolaris snv_89 All x86 All
Operating System Sun Opensolaris snv_90 All sparc All
Operating System Sun Opensolaris snv_90 All x86 All
Operating System Sun Opensolaris snv_91 All sparc All
Operating System Sun Opensolaris snv_91 All x86 All
Operating System Sun Opensolaris snv_92 All sparc All
Operating System Sun Opensolaris snv_92 All x86 All
Operating System Sun Opensolaris snv_93 All sparc All
Operating System Sun Opensolaris snv_93 All x86 All
Operating System Sun Opensolaris snv_94 All sparc All
Operating System Sun Opensolaris snv_94 All x86 All
Operating System Sun Opensolaris snv_95 All sparc All
Operating System Sun Opensolaris snv_95 All x86 All
Operating System Sun Opensolaris snv_96 All sparc All
Operating System Sun Opensolaris snv_96 All x86 All
Operating System Sun Opensolaris snv_97 All sparc All
Operating System Sun Opensolaris snv_97 All x86 All
Operating System Sun Opensolaris snv_98 All sparc All
Operating System Sun Opensolaris snv_98 All x86 All
Operating System Sun Opensolaris snv_99 All sparc All
Operating System Sun Opensolaris snv_99 All x86 All
Operating System Sun Solaris 10.0 All sparc All
Operating System Sun Solaris 10.0 All x86 All
Operating System Sun Solaris 8.0 All sparc All
Operating System Sun Solaris 8.0 All x86 All
Operating System Sun Solaris 9.0 All sparc All
Operating System Sun Solaris 9.0 All x86 All
Operating System Ubuntu Ubuntu Linux 6.06 _nil_ lts All
Operating System Ubuntu Ubuntu Linux 6.10 All All All
Operating System Ubuntu Ubuntu Linux 7.04 All All All
Operating System Ubuntu Ubuntu Linux 7.10 All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Na N/a affected n/a Not specified

References

ReferenceSourceLinkTags
sunsolve.sun.com/search/document.do af854a3a-2127-422b-91ae-364da2661108 sunsolve.sun.com
OpenBSD dhcpd Buffer Overflow Vulnerability - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
sunsolve.sun.com/search/document.do af854a3a-2127-422b-91ae-364da2661108 sunsolve.sun.com
www.coresecurity.com/index.php5 af854a3a-2127-422b-91ae-364da2661108 www.coresecurity.com
CVS log for src/usr.sbin/dhcpd/options.c af854a3a-2127-422b-91ae-364da2661108 www.openbsd.org Patch
IBM X-Force Exchange af854a3a-2127-422b-91ae-364da2661108 exchange.xforce.ibmcloud.com
OpenBSD dhcpd Buffer Overflow Lets Remote Users Execute Arbitrary Code - SecurityTracker af854a3a-2127-422b-91ae-364da2661108 www.securitytracker.com
USN-531-1: dhcp vulnerability | Ubuntu af854a3a-2127-422b-91ae-364da2661108 www.ubuntu.com
Sun Solaris DHCP Denial of Service And Remote Code Execution Vulnerabilities af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
Ubuntu update for dhcp - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
USN-531-2: dhcp vulnerability | Ubuntu af854a3a-2127-422b-91ae-364da2661108 www.ubuntu.com
Debian -- Security Information -- DSA-1388-3 dhcp af854a3a-2127-422b-91ae-364da2661108 www.debian.org
ISC DHCPD Server Remote Stack Corruption Vulnerability af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com Patch
Red Hat update for dhcp - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Vendor Advisory
Ubuntu 6.06 DHCPd bug Remote Denial of Service Exploit af854a3a-2127-422b-91ae-364da2661108 www.exploit-db.com
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
OpenBSD 4.1 errata af854a3a-2127-422b-91ae-364da2661108 www.openbsd.org Patch
Solaris DHCP Daemon Bug Lets Remote Users Deny Service - SecurityTracker af854a3a-2127-422b-91ae-364da2661108 securitytracker.com
OpenBSD 4.2 errata af854a3a-2127-422b-91ae-364da2661108 www.openbsd.org Patch
Sun Solaris DHCP Request Handling Vulnerabilities - Advisories - Community af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Debian update for dhcp - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Repository / Oval Repository af854a3a-2127-422b-91ae-364da2661108 oval.cisecurity.org
OpenBSD 4.0 errata af854a3a-2127-422b-91ae-364da2661108 www.openbsd.org Patch
#446354 - dhcp: stack-based buffer overflow (CVE-2007-5365) - Debian Bug report logs af854a3a-2127-422b-91ae-364da2661108 bugs.debian.org
Support af854a3a-2127-422b-91ae-364da2661108 www.redhat.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report