Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()
Vulnerability Description
dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
跨界内存写
Vulnerability Title
NetworkConfiguration dhcpcd 缓冲区错误漏洞
Vulnerability Description
NetworkConfiguration dhcpcd是NetworkConfiguration团队的一款DHCP客户端软件。 NetworkConfiguration dhcpcd 10.3.2及之前版本存在缓冲区错误漏洞,该漏洞源于src/dhcp6.c中的dhcp6_makemessage()函数存在单字节栈越界写入,未经身份验证的同链路攻击者可通过序列化过大的OPTION_PD_EXCLUDE选项体,写入固定本地缓冲区之外,从而触发越界写入并可能破坏相邻堆栈内存。
CVSS Information
N/A
Vulnerability Type
N/A