Severity: Unknown
Affected Package: dhclient
Summary: Heap overflow in dhclient(8) DHCP option 119 parsing
When parsing DHCP option 119 data, dhclient(8) computes the uncompressed domain search list length in order to allocate a buffer. The length computation failed to handle certain malformed input, resulting in a heap overflow when the uncompressed list was copied into an inadequately sized buffer. A malicious DHCP server, or an attacker able to spoof DHCP responses, could exploit this.
No specific recommendations provided.
Aliases: CVE-2020-7461
Published: September 02, 2020
Last Modified: September 02, 2020