Unrated severityNVD Advisory· Published Mar 1, 2005· Updated Apr 16, 2026
CVE-2004-1006
CVE-2004-1006
Description
Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.
Affected products
22cpe:2.3:a:isc:dhcpd:2.0.pl5:*:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:isc:dhcpd:2.0.pl5:*:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc1:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc10:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc11:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc12:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc13:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc14:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc2:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc3:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc4:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc5:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc6:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc7:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc8:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0.1:rc9:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0_b2pl23:*:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0_b2pl9:*:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0_pl1:*:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0_pl2:*:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0:rc12:*:*:*:*:*:*
- cpe:2.3:a:isc:dhcpd:3.0:rc4:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.debian.org/security/2004/dsa-584nvdPatchVendor Advisory
- www.securityfocus.com/bid/11591nvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/448384nvdUS Government Resource
- archives.neohapsis.com/archives/bugtraq/2004-10/0287.htmlnvd
- archives.neohapsis.com/archives/bugtraq/2004-11/0037.htmlnvd
- marc.infonvd
- www.redhat.com/support/errata/RHSA-2005-212.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17963nvd
News mentions
0No linked articles in our index yet.