Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: dhcpcd
Date: Sun, 05 Jan 2003 01:10:34
Message-Id: 20030105003033.E7E375763@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200301-3
6 - - --------------------------------------------------------------------
7
8 PACKAGE : dhcpcd
9 SUMMARY : remote command execution
10 DATE    : 2003-01-05 00:01 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 When assigning an IP address to a network interface, dhcpcd may
16 execute an external script, '/sbin/dhcpd-<interface>.exe'.
17 This is an optional configuration that must be setup manually on
18 Gentoo Linux systems by copying the script
19 into /sbin/.
20
21 The script 'dhcpcd-<interface>.exe' uses values from
22 '/var/lib/dhcpcd/dhcpcd-<interface>.info', which originate from the
23 DHCP server. A lack of input validation on this data may make it
24 possible for commands injected by a malicious DHCP server to be
25 executed through the use of shell metacharacters such as ';' and '|'.
26 These commands may run with root privileges.
27
28 More information is available at
29 http://online.securityfocus.com/bid/6200/info/
30
31 SOLUTION
32
33 It is recommended that all Gentoo Linux users who are running
34 net-misc/dhcpcd-1.3.20_p0-r1 or earlier update their systems as
35 follows:
36
37 emerge rsync
38 emerge dhcpcd
39 emerge clean
40
41 - - --------------------------------------------------------------------
42 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
43 - - --------------------------------------------------------------------
44 -----BEGIN PGP SIGNATURE-----
45 Version: GnuPG v1.2.1 (GNU/Linux)
46
47 iD8DBQE+F3zufT7nyhUpoZMRAm+hAKCzOXX6yIYWnhHXWYclGaTAmvx5iQCffolq
48 /YhKi+P23DLiTsUoL9l5B98=
49 =sCso
50 -----END PGP SIGNATURE-----