Back
CVE-2004-1006
Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.
Published: Mar 1, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (22)
| Vendor | Product | Version |
|---|---|---|
| isc | dhcpd | 2.0.pl5 |
| isc | dhcpd | 3.0 |
| isc | dhcpd | 3.0 |
| isc | dhcpd | 3.0 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0.1 |
| isc | dhcpd | 3.0_b2pl9 |
| isc | dhcpd | 3.0_b2pl23 |
…and 2 more
GitHub Security Advisory GHSA-3f5j-qwg9-83wr
Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers...
References (16)
- http://archives.neohapsis.com/archives/bugtraq/2004-10/0287.html
- http://archives.neohapsis.com/archives/bugtraq/2004-11/0037.html
- http://marc.info/?l=bugtraq&m=109968710822449&w=2
- http://www.debian.org/security/2004/dsa-584 Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/448384 US Government Resource
- http://www.redhat.com/support/errata/RHSA-2005-212.html
- http://www.securityfocus.com/bid/11591 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17963
- http://archives.neohapsis.com/archives/bugtraq/2004-10/0287.html
- http://archives.neohapsis.com/archives/bugtraq/2004-11/0037.html
- http://marc.info/?l=bugtraq&m=109968710822449&w=2
- http://www.debian.org/security/2004/dsa-584 Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/448384 US Government Resource
- http://www.redhat.com/support/errata/RHSA-2005-212.html
- http://www.securityfocus.com/bid/11591 Patch, Vendor Advisory
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
7.97%
Top 6% most likely to be exploited
Threat Score
42.4 / 100
Data Sources
NVD
EPSS
GitHub