dhcpcd: Arbitrary code execution
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201301-04 / dhcpcd |
| Release Date |
January 09, 2013 |
| Latest Revision |
January 09, 2013: 1 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/dhcpcd |
<
5.2.12 |
>=
5.2.12 |
All supported architectures
|
Related bugreports:
#362459
Synopsis
A vulnerability has been found in dhcpcd, allowing remote attackers
to execute arbitrary code on the DHCP client.
2.
Impact Information
Background
dhcpcd is a fully featured, yet light weight RFC2131 compliant DHCP
client.
Description
A vulnerability has been discovered in dhcpcd. Please review the CVE
identifier referenced below for details.
Impact
The vulnerability might allow an attacker to execute arbitrary code on
the DHCP client.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All dhcpcd users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/dhcpcd-5.2.12"
|
4.
References
|