CVE-2014-7913

Priority
Description
The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used
in dhcp.c in dhcpcd 5.x in Android before 5.1 and other products,
misinterprets the return value of the snprintf function, which allows
remote DHCP servers to execute arbitrary code or cause a denial of service
(memory corruption) via a crafted message.
Notes
Package
Upstream:needed
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needed)
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 20.04 LTS (Focal Fossa):DNE
Ubuntu 20.10 (Groovy Gorilla):DNE
Package
Upstream:needed
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needed)
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):not-affected
Ubuntu 20.04 LTS (Focal Fossa):not-affected
Ubuntu 20.10 (Groovy Gorilla):not-affected
Patches:
Other:https://android.googlesource.com/platform/external/dhcpcd/+/73c09dd8067250734511d955d8f792b41c7213f0
More Information

Updated: 2020-07-28 18:25:44 UTC (commit 7b6828437fde0509248708fcdb5b0f7587b85bd1)