LWN.net Logo

busybox: code execution

Package(s):busybox CVE #(s):CVE-2011-2716
Created:February 21, 2012 Updated:July 19, 2012
Description: From the Red Hat advisory:

The BusyBox DHCP client, udhcpc, did not sufficiently sanitize certain options provided in DHCP server replies, such as the client hostname. A malicious DHCP server could send such an option with a specially-crafted value to a DHCP client. If this option's value was saved on the client system, and then later insecurely evaluated by a process that assumes the option is trusted, it could lead to arbitrary code execution with the privileges of that process. Note: udhcpc is not used on Red Hat Enterprise Linux by default, and no DHCP client script is provided with the busybox packages.

Alerts:
Red Hat RHSA-2012:0308-03 2012-02-21
Oracle ELSA-2012-0308 2012-03-07
Scientific Linux SL-busy-20120321 2012-03-21
Red Hat RHSA-2012:0810-04 2012-06-20
Oracle ELSA-2012-0810 2012-07-02
Scientific Linux SL-busy-20120709 2012-07-09
CentOS CESA-2012:0810 2012-07-10
Mageia MGASA-2012-0171 2012-07-19
Mageia MGASA-2012-0172 2012-07-19
Mandriva MDVSA-2012:129 2012-08-10
Mandriva MDVSA-2012:129-1 2012-08-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds