← Back

CVE-2020-7461

nvd nist
Published: Mar 26, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, dhclient(8) fails to handle certain malformed input related to handling of DHCP option 119 resulting a heap overflow. The heap overflow could in principle be exploited to achieve remote code execution. The affected process runs with reduced privileges in a Capsicum sandbox, limiting the immediate impact of an exploit.

Affected (27)

1 product
Freebsd
2 products
Simatic Rf350m Firmware
Simatic Rf650m Firmware
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 11.3
Version 11.3 p10
Version 11.3 p11
Version 11.3 p12
Version 11.3 p1
Version 11.3 p2
Version 11.3 p3
Version 11.3 p4
Version 11.3 p5
Version 11.3 p6
Version 11.3 p7
Version 11.3 p8
Version 11.3 p9
Version 11.4
Version 11.4 p1
Version 11.4 p2
Version 12.1
Version 12.1 p1
Version 12.1 p2
Version 12.1 p3
Version 12.1 p4
Version 12.1 p5
Version 12.1 p6
Version 12.1 p7
Version 12.1 p8
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Rf350m
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Rf650m
All versions

References (4)

Source: secteam@freebsd.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.