CVE-2002-0702

ISC DHCPd 3-3.0.1rc8 - Remote Code Execution via Format String in DNS Response

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0702. PoCs published by Andi.

AI-analyzed exploit summary This exploit leverages a format string vulnerability in ISC DHCPD 3.0 to achieve remote code execution by crafting a malicious DHCP request. It uses a custom DHCP client configuration to inject shellcode and overwrite return addresses on the stack.

Description

Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS server response.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Andi · cremotebsd
https://www.exploit-db.com/exploits/21440

This exploit leverages a format string vulnerability in ISC DHCPD 3.0 to achieve remote code execution by crafting a malicious DHCP request. It uses a custom DHCP client configuration to inject shellcode and overwrite return addresses on the stack.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: ISC DHCPD 3.0
No auth needed
Prerequisites: NSUPDATE configuration option enabled (default in 3.0+) · Ability to send DHCP requests to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4701
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/854315
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2002-12.html
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000483
Patch, Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-037.php
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2002_19_dhcp.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102089498828206&w=2
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0063.html
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9039.php
Various Sources vendor-advisory x_refsource_caldera
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-028.0.txt

Scores

EPSS 0.3114
EPSS Percentile 98.0%

Details

Status published
Products (2)
isc/dhcpd 3.0
isc/dhcpd 3.0.1 rc1 (8 CPE variants)
Published Jul 26, 2002
Tracked Since Feb 18, 2026