{"id":"DSA-219","summary":"dhcpcd - remote command execution","details":"\nSimon Kelly discovered a vulnerability in dhcpcd, an RFC2131 and\nRFC1541 compliant DHCP client daemon, that runs with root privileges\non client machines. A malicious administrator of the regular or an\nuntrusted DHCP server may execute any command with root privileges on\nthe DHCP client machine by sending the command enclosed in shell\nmetacharacters in one of the options provided by the DHCP server.\n\n\nThis problem has been fixed in version 1.3.17pl2-8.1 for the old\nstable distribution (potato) and in version 1.3.22pl2-2 for the\ntesting (sarge) and unstable (sid) distributions. The current stable\ndistribution (woody) does not contain a dhcpcd package.\n\n\nWe recommend that you upgrade your dhcpcd package (on the client\nmachine).\n\n\n","modified":"2022-07-04T02:00:37.342024Z","published":"2002-12-31T00:00:00Z","withdrawn":"2024-05-15T05:36:14.128190Z","schema_version":"1.7.3"}