CVE-2014-7912
The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products, does not validate the relationship between length fields and the amount of data, which allows remote DHCP servers to execute…
Does this matter?
Lower severity and a low EPSS score (2.65%). Track it; it rarely justifies an emergency change on its own.
Description
The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products, does not validate the relationship between length fields and the amount of data, which allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a large length value of an option in a DHCPACK message.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.65% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- dhcpcd project/dhcpcd
- Source
- chrome-cve-admin@google.com
References
- http://www.securitytracker.com/id/1033124
- http://www.zerodayinitiative.com/advisories/ZDI-15-093/
- https://android.googlesource.com/platform/external/dhcpcd/+/73c09dd8067250734511d955d8f792b41c7213f0
- http://www.securitytracker.com/id/1033124
- http://www.zerodayinitiative.com/advisories/ZDI-15-093/
- https://android.googlesource.com/platform/external/dhcpcd/+/73c09dd8067250734511d955d8f792b41c7213f0
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.