Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h949-qrpv-p29v

Опубликовано: 22 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

EPSS

Процентиль: 96%
0.28991
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

CVSS3: 9.8
nvd
около 6 лет назад

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

CVSS3: 9.8
debian
около 6 лет назад

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /t ...

EPSS

Процентиль: 96%
0.28991
Средний

9.8 Critical

CVSS3