← Vulnerability feed

Vulnerability record · CVE-2007-5365 · published 11 October 2007

CVE-2007-5365: OpenBSD dhcpd cons_options stack buffer overflow via DHCP request

Debian · Debian Linux

The cons_options function in dhcpd's options.c contains a stack-based buffer overflow when a DHCP request specifies a maximum message size smaller than the minimum IP MTU. This affects OpenBSD 4.0 through 4.2 and other dhcpd implementations derived from ISC dhcp-2. A remote attacker can crash the daemon or potentially execute arbitrary code, making it a serious pre-authentication flaw in a core network service.

7.2 CVSS 2.0 High EPSS 80% · top 0.4% CWE-119 · Memory buffer overflow
7.2CVSS 2.0 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
54References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw is a remotely reachable memory corruption in a core network service with a high EPSS score, though no confirmed exploitation or KEV listing is present.

What it is

The cons_options function in dhcpd's options.c contains a stack-based buffer overflow when a DHCP request specifies a maximum message size smaller than the minimum IP MTU. This affects OpenBSD 4.0 through 4.2 and other dhcpd implementations derived from ISC dhcp-2. A remote attacker can crash the daemon or potentially execute arbitrary code, making it a serious pre-authentication flaw in a core network service.

Impact

An attacker can cause a denial of service by crashing dhcpd, and the overflow may allow arbitrary code execution in the context of the dhcpd process. Successful exploitation could disrupt DHCP service or compromise the host running the daemon.

Attack surface

The flaw is reached through a crafted DHCP request sent to the dhcpd service, which is normally network-facing and requires no authentication. The CVSS vector is recorded as AV:L, which conflicts with the description of a remote attacker; the record does not reconcile this discrepancy.

Exploitation

No public exploitation is confirmed by the record: CVE-2007-5365 is not listed in CISA KEV, no ransomware groups are documented, and references carry only Patch and Vendor Advisory tags. EPSS is high at 0.80265 (99.6th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply the OpenBSD errata patches for 4.0, 4.1 and 4.2, or the corresponding vendor updates from Debian, Red Hat, Ubuntu and Sun.
  • Upgrade or replace dhcpd implementations based on ISC dhcp-2 that have not received the fix.
  • Restrict DHCP traffic to trusted network segments and block DHCP from untrusted or external networks at the perimeter.
  • Monitor vendor advisories for updated packages and redeploy patched dhcpd builds.
  • If patching is delayed, isolate or disable dhcpd on systems that do not require it.

Detection

  • Monitor dhcpd logs and system logs for crashes, restarts or abnormal termination.
  • Inspect DHCP request traffic for maximum message size values below the minimum IP MTU.
  • Use host or network IDS signatures for malformed DHCP options targeting dhcpd.
  • Track unexpected dhcpd process exits or core dumps on DHCP servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446354
http://secunia.com/advisories/27160 Vendor Advisory
http://secunia.com/advisories/27273 Vendor Advisory
http://secunia.com/advisories/27338 Vendor Advisory
http://secunia.com/advisories/27350 Vendor Advisory
http://secunia.com/advisories/32668 Vendor Advisory
http://securitytracker.com/id?1021157
http://sunsolve.sun.com/search/document.do?assetkey=1-21-109077-21-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-243806-1
http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1962
http://www.debian.org/security/2007/dsa-1388
http://www.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/dhcpd/options.c Patch
http://www.openbsd.org/errata40.html#016_dhcpd Patch
http://www.openbsd.org/errata41.html#010_dhcpd Patch
http://www.openbsd.org/errata42.html#001_dhcpd Patch
http://www.redhat.com/support/errata/RHSA-2007-0970.html
http://www.securityfocus.com/archive/1/482085/100/100/threaded
http://www.securityfocus.com/archive/1/483230/100/100/threaded
http://www.securityfocus.com/bid/25984 Patch
http://www.securityfocus.com/bid/32213
http://www.securitytracker.com/id?1018794
http://www.ubuntu.com/usn/usn-531-1
http://www.ubuntu.com/usn/usn-531-2
http://www.vupen.com/english/advisories/2008/3088 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/37045
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5817
https://www.exploit-db.com/exploits/4601
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446354
http://secunia.com/advisories/27160 Vendor Advisory
http://secunia.com/advisories/27273 Vendor Advisory
http://secunia.com/advisories/27338 Vendor Advisory
http://secunia.com/advisories/27350 Vendor Advisory
http://secunia.com/advisories/32668 Vendor Advisory
http://securitytracker.com/id?1021157
http://sunsolve.sun.com/search/document.do?assetkey=1-21-109077-21-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-243806-1
http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1962
http://www.debian.org/security/2007/dsa-1388
http://www.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/dhcpd/options.c Patch
http://www.openbsd.org/errata40.html#016_dhcpd Patch

Track CVE-2007-5365 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2007-5365), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.