peter bassill · operator
$ cve CVE-2009-0692 JSON

CVE-2009-0692 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 25.8% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS25.78% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-07-14
Last modified2026-06-16

Affected (1)

VendorProduct
iscdhcp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD