PT-2002-1779 · Suse · Sysconfig
Publicado
2002-08-12
·
Atualizado
2008-09-10
·
CVE-2002-0758
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sysconfig package for SuSE version 8.0
Description
The ifup-dhcp script in the sysconfig package allows remote attackers to execute arbitrary commands via spoofed DHCP responses. These responses are stored and executed in a file, enabling the attacker to perform unauthorized actions.
Recommendations
For SuSE 8.0, consider disabling the ifup-dhcp script until a patch is available to prevent the execution of arbitrary commands via spoofed DHCP responses. Restrict access to the affected script to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sysconfig