← Vulnerability feed

Vulnerability record · CVE-2009-0692 · published 14 July 2009

CVE-2009-0692: Isc dhcp memory buffer overflow vulnerability

Isc · Dhcp

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

10.0 CVSS 2.0 High EPSS 26% · top 2.1% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
72References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-010.txt.asc
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00003.html
http://secunia.com/advisories/35785 Vendor Advisory
http://secunia.com/advisories/35829
http://secunia.com/advisories/35830
http://secunia.com/advisories/35831
http://secunia.com/advisories/35832
http://secunia.com/advisories/35841
http://secunia.com/advisories/35849
http://secunia.com/advisories/35850
http://secunia.com/advisories/35851
http://secunia.com/advisories/35880
http://secunia.com/advisories/36457
http://secunia.com/advisories/37342
http://secunia.com/advisories/40551
http://security.gentoo.org/glsa/glsa-200907-12.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561471
http://www.debian.org/security/2009/dsa-1833
http://www.kb.cert.org/vuls/id/410676 US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2009:151
http://www.osvdb.org/55819
http://www.redhat.com/support/errata/RHSA-2009-1136.html
http://www.redhat.com/support/errata/RHSA-2009-1154.html
http://www.securityfocus.com/bid/35668
http://www.securitytracker.com/id?1022548
http://www.ubuntu.com/usn/usn-803-1
http://www.vupen.com/english/advisories/2009/1891
http://www.vupen.com/english/advisories/2010/1796
https://bugzilla.redhat.com/show_bug.cgi?id=507717
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10758
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5941
https://www.isc.org/downloadables/12
https://www.isc.org/node/468 PatchVendor Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01177.html
https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00340.html
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-010.txt.asc
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00003.html
http://secunia.com/advisories/35785 Vendor Advisory

Track CVE-2009-0692 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2011-2748Isc dhcp improper input validation vulnerabilityThe server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…EPSS 39%7.8CVE-2011-2749Isc dhcp improper input validation vulnerabilityThe server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…EPSS 39%7.8CVE-2011-0413Isc dhcp improper input validation vulnerabilityThe DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attacker…EPSS 33%7.5CVE-2018-5732Isc dhcp memory buffer overflow vulnerabilityFailure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause…EPSS 5.2%7.5CVE-2017-3144ISC DHCP OMAPI connection cleanup failure exhausts socket descriptorsISC DHCP fails to properly clean up closed OMAPI connections, so socket descriptors are not released back to the server's pool. Repeated connections …EPSS 73%analysed7.5CVE-2018-5733Isc dhcp integer overflow vulnerabilityA malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit ref…EPSS 20%7.5CVE-2011-0997ISC DHCP dhclient command injection via DHCP hostnamedhclient in ISC DHCP 3.0.x through 4.2.x (before 4.2.1-P1), 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 fails to validate the hostname o…EPSS 84%analysed7.4CVE-2021-25217Isc dhcp memory buffer overflow vulnerabilityIn ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases …EPSS 6.1%

Source: NIST National Vulnerability Database (record CVE-2009-0692), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.