SuSE IfUp-DHCP Script Remote Arbitrary Command Execution Vulnerability
BID:4695
Info
SuSE IfUp-DHCP Script Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 4695 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2002 12:00AM |
| Updated: | May 08 2002 12:00AM |
| Credit: | Vulnerability announced by SuSE. |
| Vulnerable: |
SuSE Linux 8.0 i386 |
| Not Vulnerable: | |
Discussion
SuSE IfUp-DHCP Script Remote Arbitrary Command Execution Vulnerability
ifup-dhcp is part of the sysconfig package included with SuSE Linux. It is freely available, and open source.
It is possible to remotely execute commands on a system using the ifup-dhcp script. Due to insufficient handling of input by the ifup-dhcp script, it is possible to send custom-crafted packets to a vulnerable host that will be interpreted as commands. This could allow an attacker to execute commands as the user executing the ifup-dhcp script (typically root).
ifup-dhcp is part of the sysconfig package included with SuSE Linux. It is freely available, and open source.
It is possible to remotely execute commands on a system using the ifup-dhcp script. Due to insufficient handling of input by the ifup-dhcp script, it is possible to send custom-crafted packets to a vulnerable host that will be interpreted as commands. This could allow an attacker to execute commands as the user executing the ifup-dhcp script (typically root).
Exploit / POC
SuSE IfUp-DHCP Script Remote Arbitrary Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SuSE IfUp-DHCP Script Remote Arbitrary Command Execution Vulnerability
Solution:
Fixes available:
SuSE Linux 8.0 i386
Solution:
Fixes available:
SuSE Linux 8.0 i386
-
SuSE sysconfig-0.23.14-60.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/a1/sysconfig-0.23.14-60.i3 86.rpm
References
SuSE IfUp-DHCP Script Remote Arbitrary Command Execution Vulnerability
References:
References: