DHCPCD Character Expansion Remote Command Execution Vulnerability
BID:6200
Info
DHCPCD Character Expansion Remote Command Execution Vulnerability
| Bugtraq ID: | 6200 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1403 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | Vulnerability announced in a Conectiva security advisory. |
| Vulnerable: |
Phystech dhcpcd 1.3.22 -pl1 Phystech dhcpcd 1.3.17 -pl2 |
| Not Vulnerable: |
Phystech dhcpcd 1.3.22 -pl3 Phystech dhcpcd 1.3.22 -pl2 |
Discussion
DHCPCD Character Expansion Remote Command Execution Vulnerability
When assigning an IP address to a network interface, dhcpcd may execute an external script, '/sbin/dhcpd-<interface>.exe'. This is an optional configuration that must be setup manually on Conectiva systems (others are not confirmed) by copying the script into /sbin/.
The script 'dhcpcd-<interface>.exe' uses values from '/var/lib/dhcpcd/dhcpcd-<interface>.info', which originate from the DHCP server. A lack of input validation on this data may make it possible for commands injected by a malicious DHCP server to be executed through the use of shell metacharacters such as ';' and '|'. These commands may run with root privileges.
When assigning an IP address to a network interface, dhcpcd may execute an external script, '/sbin/dhcpd-<interface>.exe'. This is an optional configuration that must be setup manually on Conectiva systems (others are not confirmed) by copying the script into /sbin/.
The script 'dhcpcd-<interface>.exe' uses values from '/var/lib/dhcpcd/dhcpcd-<interface>.info', which originate from the DHCP server. A lack of input validation on this data may make it possible for commands injected by a malicious DHCP server to be executed through the use of shell metacharacters such as ';' and '|'. These commands may run with root privileges.
Exploit / POC
DHCPCD Character Expansion Remote Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
DHCPCD Character Expansion Remote Command Execution Vulnerability
Solution:
Conectiva has released a security advisory. Fixes are available.
It is recommended that all Gentoo Linux users who are running
net-misc/dhcpcd-1.3.20_p0-r1 or earlier update their systems as
follows:
emerge rsync
emerge dhcpcd
emerge clean
The vendor has addressed the issue in the latest dhcpcd release.
Fixes:
Phystech dhcpcd 1.3.17 -pl2
Phystech dhcpcd 1.3.22 -pl1
Solution:
Conectiva has released a security advisory. Fixes are available.
It is recommended that all Gentoo Linux users who are running
net-misc/dhcpcd-1.3.20_p0-r1 or earlier update their systems as
follows:
emerge rsync
emerge dhcpcd
emerge clean
The vendor has addressed the issue in the latest dhcpcd release.
Fixes:
Phystech dhcpcd 1.3.17 -pl2
-
Debian dhcpcd_1.3.17pl2-8.1_alpha.deb
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.17pl2 -8.1_alpha.deb -
Debian dhcpcd_1.3.17pl2-8.1_arm.deb
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.17pl2 -8.1_arm.deb -
Debian dhcpcd_1.3.17pl2-8.1_i386.deb
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.17pl2 -8.1_i386.deb -
Debian dhcpcd_1.3.17pl2-8.1_m68k.deb
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.17pl2 -8.1_m68k.deb -
Debian dhcpcd_1.3.17pl2-8.1_powerpc.deb
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.17pl2 -8.1_powerpc.deb -
Debian dhcpcd_1.3.17pl2-8.1_sparc.deb
http://security.debian.org/pool/updates/main/d/dhcpcd/dhcpcd_1.3.17pl2 -8.1_sparc.deb
Phystech dhcpcd 1.3.22 -pl1
-
Conectiva dhcpcd-1.3.22pl3-1U60_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/dhcpcd-1.3.22pl3-1U60_2cl .i386.rpm -
Conectiva dhcpcd-1.3.22pl3-1U60_2cl.src.rpm
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/dhcpcd-1.3.22pl3-1U60_2c l.src.rpm -
Conectiva dhcpcd-1.3.22pl3-1U70_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/dhcpcd-1.3.22pl3-1U70_1c l.src.rpm -
Conectiva dhcpcd-1.3.22pl3-1U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/dhcpcd-1.3.22pl3-1U80_1cl.i 386.rpm -
Conectiva dhcpcd-1.3.22pl3-1U80_1cl.src.rpm
ftp://atualizacoes.conectiva.com.br/8/SRPMS/dhcpcd-1.3.22pl3-1U80_1cl. src.rpm -
MandrakeSoft dhcpcd-1.3.22pl4-1.1mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft dhcpcd-1.3.22pl4-1.1mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft dhcpcd-1.3.22pl4-1.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft dhcpcd-1.3.22pl4-1.1mdk.i586.rpm
Multi Network Firewall 8.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft dhcpcd-1.3.22pl4-1.1mdk.i586.rpm
Single Network Firewall 7.2
http://www.mandrakesecure.net/en/ftp.php -
MandrakeSoft dhcpcd-1.3.22pl4-1.1mdk.ppc.rpm
Mandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php -
Phystech dhcpcd-1.3.22-pl2
http://www.phystech.com/download/ -
Phystech dhcpcd-1.3.22-pl3
http://www.phystech.com/download/