Oval Definition:oval:org.mitre.oval:def:12297
Revision Date:2014-07-21Version:20
Title:DSA-2217-1 dhcp3 -- missing input sanitisation
Description:Sebastian Krahmer and Marius Tomaschewski discovered that dhclient of dhcp3, a DHCP client, is not properly filtering shell meta-characters in certain options in DHCP server responses. These options are reused in an insecure fashion by dhclient scripts. This allows an attacker to execute arbitrary commands with the privileges of such a process by sending crafted DHCP options to a client using a rogue server.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2011-0997
DSA-2217-1
Platform(s):Debian GNU/Linux 5.0
Product(s):dhcp3
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Installed architecture is all
  • AND dhcp3 DPKG is earlier than 3.1.1-6+lenny5
  • BACK