7.5
CVSSv3

CVE-2016-1504

Published: 07/02/2017 Updated: 10/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

dhcpcd prior to 6.10.0 allows remote malicious users to cause a denial of service (invalid read and crash) via vectors related to the option length.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dhcpcd project dhcpcd

Vendor Advisories

Debian Bug report logs - #810621 dhcpcd5: CVE-2016-1503: heap overflow via malformed dhcp responses in print_option (via dhcp_envoption1) due to incorrect option length values Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...
Debian Bug report logs - #810620 dhcpcd5: CVE-2016-1504: invalid read/crash via malformed dhcp responses Package: src:dhcpcd5; Maintainer for src:dhcpcd5 is Scott Leggett <scott@slidau>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 10 Jan 2016 16:27:02 UTC Severity: important Tags: fixed-upstrea ...