Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24453
HistoryApr 10, 2020 - 12:54 a.m.

Arbitrary Code Execution

2020-04-1000:54:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.969 High

EPSS

Percentile

99.7%

dhcp is vulnerable to arbitrary code execution. It was discovered that the DHCP client daemon, dhclient, did not sufficiently sanitize certain options provided in DHCP server replies, such as the client hostname. A malicious DHCP server could send such an option with a specially-crafted value to a DHCP client. If this option’s value was saved on the client system, and then later insecurely evaluated by a process that assumes the option is trusted, it could lead to arbitrary code execution with the privileges of that process.

References