dhcpcd 'hostname' Remote Arbitrary Shell Command Injection Vulnerability
BID:47272
Info
dhcpcd 'hostname' Remote Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 47272 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0996 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2011 12:00AM |
| Updated: | Jan 09 2013 06:20AM |
| Credit: | SUSE |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 10 SP4 SuSE SUSE Linux Enterprise 10 SP3 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux -current S.u.S.E. openSUSE 11.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 Pardus Linux 2011 0 Pardus Linux 2009 0 Gentoo Linux dhcpcd dhcpcd 5.2.10 |
| Not Vulnerable: |
dhcpcd dhcpcd 5.2.12 |
Discussion
dhcpcd 'hostname' Remote Arbitrary Shell Command Injection Vulnerability
dhcpcd is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the application.
dhcpcd versions prior to 5.2.12 are vulnerable.
dhcpcd is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the application.
dhcpcd versions prior to 5.2.12 are vulnerable.
Exploit / POC
dhcpcd 'hostname' Remote Arbitrary Shell Command Injection Vulnerability
Attackers can exploit this issue using standard tools.
Attackers can exploit this issue using standard tools.
Solution / Fix
dhcpcd 'hostname' Remote Arbitrary Shell Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 13.0 x86_64
Slackware Linux x86_64 -current
Slackware Linux -current
Slackware Linux 13.37 x86_64
Slackware Linux 13.0
Slackware Linux 13.1 x86_64
Slackware Linux 13.1
Slackware Linux 13.37
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 13.0 x86_64
-
Slackware dhcpcd-3.2.3-x86_64-2_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/dhcpcd-3.2.3-x86_64-2_slack13.0.txz
Slackware Linux x86_64 -current
-
Slackware dhcpcd-5.2.12-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ n/dhcpcd-5.2.12-x86_64-1.txz
Slackware Linux -current
-
Slackware dhcpcd-5.2.12-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/dh cpcd-5.2.12-i486-1.txz
Slackware Linux 13.37 x86_64
-
Slackware dhcpcd-5.2.12-x86_64-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packag es/dhcpcd-5.2.12-x86_64-1_slack13.37.txz
Slackware Linux 13.0
-
Slackware dhcpcd-3.2.3-i486-2_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/ dhcpcd-3.2.3-i486-2_slack13.0.txz
Slackware Linux 13.1 x86_64
-
Slackware dhcpcd-5.2.12-x86_64-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/package s/dhcpcd-5.2.12-x86_64-1_slack13.1.txz
Slackware Linux 13.1
-
Slackware dhcpcd-5.2.12-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ dhcpcd-5.2.12-i486-1_slack13.1.txz
Slackware Linux 13.37
-
Slackware dhcpcd-5.2.12-i486-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages /dhcpcd-5.2.12-i486-1_slack13.37.txz
References
dhcpcd 'hostname' Remote Arbitrary Shell Command Injection Vulnerability
References:
References:
- dhcpcd Homepage (dhcpcd)
- dhcpcd Changeset (dhcpcd)
- dhcpcd Security Advisory (dhcpcd)