LWN.net Logo

connman: code execution

Package(s):connman CVE #(s):CVE-2012-2320 CVE-2012-2321 CVE-2012-2322
Created:May 16, 2012 Updated:May 16, 2012
Description: From the Gentoo advisory:

Multiple vulnerabilities have been found in ConnMan:

  • Errors in inet.c and rtnl.c prevent ConnMan from checking the origin of netlink messages (CVE-2012-2320).
  • ConnMan does not properly check for shell escapes when requesting a hostname via DHCP (CVE-2012-2321).
  • An infinite loop error exists in client.c (CVE-2012-2322).
A remote attacker could execute arbitrary code with the privileges of the process or cause a Denial of Service condition.
Alerts:
Gentoo 201205-02 2012-05-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds