PT-2019-6632 · Klibc · Klibc
Published
2019-11-14
·
Updated
2020-08-18
·
CVE-2011-1930
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
klibc versions 1.5.20 through 1.5.21
Description
The issue arises from the improper escaping of DHCP options written by ipconfig to /tmp/net-$DEVICE.conf. This could potentially allow a remote attacker to send a specially crafted DHCP reply, which may execute arbitrary code with the privileges of any process that sources DHCP options.
Recommendations
For klibc versions 1.5.20 and 1.5.21, consider restricting access to the DHCP options file until a proper fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Klibc