Vulnerability record · CVE-2004-0460 · published 6 August 2004
CVE-2004-0460: ISC DHCP dhcpd logging buffer overflow via hostname options
Infoblox · Dns One Appliance
ISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQUEST, ACK, or NAK messages can produce a long string when written to a log file, overflowing the buffer. The flaw matters because it can crash the DHCP server and potentially allow code execution.
Description
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score is 10 with network reachability, no authentication, and complete confidentiality, integrity and availability impact, and EPSS is at the 98.7th percentile.
What it is
ISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQUEST, ACK, or NAK messages can produce a long string when written to a log file, overflowing the buffer. The flaw matters because it can crash the DHCP server and potentially allow code execution.
Impact
A remote attacker can crash the DHCP daemon, causing a denial of service, and may be able to execute arbitrary code on the server. Successful code execution would give the attacker the privileges of the dhcpd process.
Attack surface
The flaw is reached over the network by sending crafted DHCP messages containing multiple hostname options; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is needed, as the trigger is the server's own logging of the malformed message.
Exploitation
CVE-2004-0460 is not listed in CISA KEV, but EPSS gives a 30-day probability of 0.45333 (98.7th percentile), indicating high predicted exploitation activity. References include a Patch and Vendor Advisory tag, but no public exploit code is confirmed in the record.
What to do
- Apply the vendor patch or upgrade to a fixed ISC DHCP release; the SecurityFocus reference is tagged Patch and Vendor Advisory.
- Restrict DHCP traffic to trusted network segments and block UDP ports 67/68 from untrusted sources at the perimeter.
- Disable or reduce verbose logging of client-supplied hostname options if the logging path cannot be patched immediately.
- Monitor vendor advisories from ISC, Red Hat, SUSE, Mandriva and Infoblox for updated fixed packages.
- Run dhcpd with least privilege and isolate it from other critical services to limit impact if code execution occurs.
Detection
- Monitor dhcpd logs for crashes, restarts, or abnormal termination correlated with DHCP client traffic.
- Inspect DHCP packets for unusually long or repeated hostname options in DISCOVER, OFFER, REQUEST, ACK, or NAK messages.
- Alert on core dumps or process failures for dhcpd on DHCP servers.
- Track DHCP server availability and log file growth for signs of malformed-message flooding.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0460 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0460), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.