|
|
| |
|
| |
busybox: code execution
| Package(s): | busybox |
CVE #(s): | CVE-2011-2716
|
| Created: | February 21, 2012 |
Updated: | July 19, 2012 |
| Description: |
From the Red Hat advisory:
The BusyBox DHCP client, udhcpc, did not sufficiently sanitize certain
options provided in DHCP server replies, such as the client hostname. A
malicious DHCP server could send such an option with a specially-crafted
value to a DHCP client. If this option's value was saved on the client
system, and then later insecurely evaluated by a process that assumes the
option is trusted, it could lead to arbitrary code execution with the
privileges of that process. Note: udhcpc is not used on Red Hat Enterprise
Linux by default, and no DHCP client script is provided with the busybox
packages. |
| Alerts: |
|
( Log in to post comments)
|
|
|