6.8
CVSSv2

CVE-2014-7913

Published: 30/07/2015 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The print_option function in dhcp-common.c in dhcpcd up to and including 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android prior to 5.1 and other products, misinterprets the return value of the snprintf function, which allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted message.

Vulnerable Product Search on Vulmon Subscribe to Product

dhcpcd_project dhcpcd

Vendor Advisories

Debian Bug report logs - #846938 dhcpcd5: CVE-2014-7913 Package: dhcpcd5; Maintainer for dhcpcd5 is Scott Leggett <scott@slidau>; Source for dhcpcd5 is src:dhcpcd5 (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 4 Dec 2016 13:54:01 UTC Severity: serious Tags: fixed-upstream, ...