← Vulnerability feed

Vulnerability record · CVE-2004-0460 · published 6 August 2004

CVE-2004-0460: ISC DHCP dhcpd logging buffer overflow via hostname options

Infoblox · Dns One Appliance

ISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQUEST, ACK, or NAK messages can produce a long string when written to a log file, overflowing the buffer. The flaw matters because it can crash the DHCP server and potentially allow code execution.

10.0 CVSS 2.0 High EPSS 45% · top 1.3%
10.0CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score is 10 with network reachability, no authentication, and complete confidentiality, integrity and availability impact, and EPSS is at the 98.7th percentile.

What it is

ISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQUEST, ACK, or NAK messages can produce a long string when written to a log file, overflowing the buffer. The flaw matters because it can crash the DHCP server and potentially allow code execution.

Impact

A remote attacker can crash the DHCP daemon, causing a denial of service, and may be able to execute arbitrary code on the server. Successful code execution would give the attacker the privileges of the dhcpd process.

Attack surface

The flaw is reached over the network by sending crafted DHCP messages containing multiple hostname options; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is needed, as the trigger is the server's own logging of the malformed message.

Exploitation

CVE-2004-0460 is not listed in CISA KEV, but EPSS gives a 30-day probability of 0.45333 (98.7th percentile), indicating high predicted exploitation activity. References include a Patch and Vendor Advisory tag, but no public exploit code is confirmed in the record.

What to do

  • Apply the vendor patch or upgrade to a fixed ISC DHCP release; the SecurityFocus reference is tagged Patch and Vendor Advisory.
  • Restrict DHCP traffic to trusted network segments and block UDP ports 67/68 from untrusted sources at the perimeter.
  • Disable or reduce verbose logging of client-supplied hostname options if the logging path cannot be patched immediately.
  • Monitor vendor advisories from ISC, Red Hat, SUSE, Mandriva and Infoblox for updated fixed packages.
  • Run dhcpd with least privilege and isolate it from other critical services to limit impact if code execution occurs.

Detection

  • Monitor dhcpd logs for crashes, restarts, or abnormal termination correlated with DHCP client traffic.
  • Inspect DHCP packets for unusually long or repeated hostname options in DISCOVER, OFFER, REQUEST, ACK, or NAK messages.
  • Alert on core dumps or process failures for dhcpd on DHCP servers.
  • Track DHCP server availability and log file growth for signs of malformed-message flooding.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0460 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6235Gnu privacy guard vulnerabilityA "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary c…EPSS 5.9%10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-1006Isc dhcpd vulnerabilityFormat string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, …EPSS 8.0%10.0CVE-2004-0989Xmlsoft libxml vulnerabilityMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code vi…EPSS 22%10.0CVE-2004-0882Samba vulnerabilityBuffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT…EPSS 14%10.0CVE-2004-0888Easy software products cups vulnerabilityMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …EPSS 9.5%10.0CVE-2004-0889Easy software products cups vulnerabilityMultiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…EPSS 6.2%10.0CVE-2004-0902Mozilla vulnerabilityMultiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote att…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2004-0460), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.