Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade isc-dhcp3-relayUpgrade isc-dhcp3Upgrade isc-dhcp3-clientUpgrade isc-dhcpdUpgrade isc-dhcp3-develUpgrade isc-dhcp3-serverUpgrade isc-dhcp | Dec 10, 2025 | Jul 23, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub