[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2217-1 dhcp3 -- missing input sanitization

ID: oval:org.secpod.oval:def:600231Date: (C)2011-04-19   (M)2022-10-10
Class: PATCHFamily: unix




Sebastian Krahmer and Marius Tomaschewski discovered that dhclient of dhcp3, a DHCP client, is not properly filtering shell meta-characters in certain options in DHCP server responses. These options are reused in an insecure fashion by dhclient scripts. This allows an attacker to execute arbitrary commands with the privileges of such a process by sending crafted DHCP options to a client using a rogue server.

Platform:
Debian 5.0
Product:
dhcp3
Reference:
DSA-2217-1
CVE-2011-0997
CVE    1
CVE-2011-0997
CPE    1
cpe:/o:debian:debian_linux:5.0

© SecPod Technologies