CVE-2004-0461 describes a critical buffer overflow vulnerability in the ISC DHCP daemon (DHCPD) versions 3.0.1rc12 and 3.0.1rc13. This flaw arises when DHCPD is compiled in environments lacking the vsnprintf function, causing it to fall back to the less secure vsprintf, leading to potential denial of service and arbitrary code execution. Affected products include Infoblox, ISC, Mandrakesoft, Red Hat, and SUSE. With a CVSS score of 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), this vulnerability is highly severe, allowing unauthenticated attackers to exploit it remotely with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score of 96/100 further emphasizes its critical nature. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community attention with 10 mentions, indicating awareness and discussion within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.1_r5CPE matchmatch criteria | cpe:2.3:h:infoblox:dns_one_appliance:2.3.1_r5:*:*:*:*:*:*:* | ||
2.4.0.8CPE matchmatch criteria | cpe:2.3:h:infoblox:dns_one_appliance:2.4.0.8:*:*:*:*:*:*:* | ||
2.4.0.8aCPE matchmatch criteria | cpe:2.3:h:infoblox:dns_one_appliance:2.4.0.8a:*:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:isc:dhcpd:3.0.1:rc12:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:isc:dhcpd:3.0.1:rc13:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.