Description
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS server response.
Exploits (1)
Scores
EPSS
0.3172
EPSS Percentile
96.8%
Details
Status
published
Products (2)
isc/dhcpd
3.0
isc/dhcpd
3.0.1 rc1 (8 CPE variants)
Published
Jul 26, 2002
Tracked Since
Feb 18, 2026