Wednesday, 6 April 2011
DHCP client allows shell command injection !
Detail: The Internet System Consortium's (ISC) open source DHCP client (dhclient) allows DHCP servers to inject commands which could allow an attacker to obtain root privileges. The problem is caused by incorrect filtering of metadata in server response fields. By using crafted host names, and depending on the operating system and what further processing is performed by dhclient-script, it
Labels:
article,
backdoor,
exploitation,
fix,
Hacking,
Information Leak,
Information Security,
linux,
security,
Security News,
Vulnerability
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment