[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2216-1 isc-dhcp -- missing input sanitization

ID: oval:org.secpod.oval:def:600233Date: (C)2011-04-19   (M)2022-10-10
Class: PATCHFamily: unix




Sebastian Krahmer and Marius Tomaschewski discovered that dhclient of isc-dhcp, a DHCP client, is not properly filtering shell meta-characters in certain options in DHCP server responses. These options are reused in an insecure fashion by dhclient scripts. This allows an attacker to execute arbitrary commands with the privileges of such a process by sending crafted DHCP options to a client using a rogue server.

Platform:
Debian 6.0
Product:
isc-dhcp
Reference:
DSA-2216-1
CVE-2011-0997
CVE    1
CVE-2011-0997
CPE    21
cpe:/a:isc:dhcp:3.1.0:b1
cpe:/a:isc:dhcp:3.1.0:b2
cpe:/a:isc:dhcp:3.1.3:rc1
cpe:/a:isc:dhcp:3.1.0:a3
...

© SecPod Technologies