← Vulnerability feed

Vulnerability record · CVE-2003-0026 · published 17 January 2003

CVE-2003-0026: Isc dhcpd vulnerability

Isc · Dhcpd

Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.

7.5 CVSS 2.0 High EPSS 19% · top 2.8%
7.5CVSS 2.0 base score
19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000562
http://www.cert.org/advisories/CA-2003-01.html PatchThird Party AdvisoryUS Government Resource
http://www.ciac.org/ciac/bulletins/n-031.shtml
http://www.debian.org/security/2003/dsa-231 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/284857 PatchThird Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:007
http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html
http://www.redhat.com/support/errata/RHSA-2003-011.html PatchVendor Advisory
http://www.securityfocus.com/bid/6627
http://www.securitytracker.com/id?1005924
http://www.suse.com/de/security/2003_006_dhcp.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/11073
http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000562
http://www.cert.org/advisories/CA-2003-01.html PatchThird Party AdvisoryUS Government Resource
http://www.ciac.org/ciac/bulletins/n-031.shtml
http://www.debian.org/security/2003/dsa-231 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/284857 PatchThird Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:007
http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html
http://www.redhat.com/support/errata/RHSA-2003-011.html PatchVendor Advisory
http://www.securityfocus.com/bid/6627
http://www.securitytracker.com/id?1005924
http://www.suse.com/de/security/2003_006_dhcp.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/11073

Track CVE-2003-0026 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1006Isc dhcpd vulnerabilityFormat string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, …EPSS 8.0%10.0CVE-2004-0460ISC DHCP dhcpd logging buffer overflow via hostname optionsISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQ…EPSS 45%analysed10.0CVE-2004-0461Infoblox dns one appliance vulnerabilityThe DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C includ…EPSS 17%10.0CVE-2002-0702Isc dhcpd vulnerabilityFormat string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE opti…EPSS 31%7.5CVE-2019-6470Isc dhcpd vulnerabilityThere had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in …EPSS 8.8%5.0CVE-2006-3122Isc dhcpd vulnerabilityThe supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) v…EPSS 4.0%5.0CVE-2003-0039Isc dhcpd vulnerabilityISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a …EPSS 8.0%

Source: NIST National Vulnerability Database (record CVE-2003-0026), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.